Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.7-debian-dev, 4.7-debian13-dev, 4.7-dev, 4.7.2-debian-dev, 4.7.2-debian13-dev, 4.7.2-dev

Index digest:

sha256:6209eb0b65e56d8aa3e3b2b2c9684dbc5ef92f3c55981ac9ef7725cfd0e5ccfa

Manifest digest:

sha256:d8788165a0700ab4fc26138b7ab51933e7bf91540c9f1f177aeb57f6cc41529b

Size

129.63 MB

Last pushed

14 hours ago

Vulnerabilities

0
3
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:2b96712294b7604c3f7420933ad9f6a70a437fb87167232afa82d65dddb61cf4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:a6917e37df85e860a605cfc484d6d44aa5394016c40f2cf0837c85e0e81f56f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:c94e0663164f1e28a47331ec0cec7f0f6e65241a5c3ba90bef74d6acaee61ab1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:da87421b31377b23e1abc31700e9b09141541a8ca5fcd02ac1ebcfa40c3a5913
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:b5a60f15de438b90a012d3cf3900e1050431c7ead120d8a1be68ee05132c47c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:471638e564343daf23273088959022952c0ebd3236e560a033da1aec951a6b9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:3aa946a885c83ba83a1ad39d57f003c79572cddde4cdb5505eb62a6d1cdcb3b5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:5651363c57d1129ae1e0a2286d413ac8c4973573e86dc627b468e26a60d41ef2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:4db2ac3871dfcd2d046a3afdce70295259e6b3876ef371eb8bf1c544632fa4d7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:a1b2f393a70b3c4a7f0378a9e8bc78873d867fb75fcae90b5d9e42fd86cbbafb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:aef0ec1dea7c16a52f70e00265a680984d2d5fe9df5203057d32cf3be84fc52d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:a498ec7ed9e05e7f2da38d6825cc82a527790bb42b6ff99f280702c1fd0e57cd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:26631399391f916d2c20f9f2c2db730067b32fc094e5d4fdfbc61c4338ea1249
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:7a5313108e2d4fbf76518666bf54b0c519ae145bd7119f49e0930db847f2b713
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:07d5578e5d7ff97c8a33e796bdb2af2dc950cfc83c51c36d58e470d8e3966439