Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (fips, dev)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.2-debian-fips-dev, 4.7.2-debian13-fips-dev, 4.7.2-fips-dev

Index digest:

sha256:35a9fed5cedd48895c4e13f5de64640cfa2dc384ef19a39a6296f9deb4d20f4f

Manifest digest:

sha256:0e73a88bf0258daa59dc52b2374b8e7c965b46831d65268bd4413604e985fb6b

Size

127.94 MB

Last pushed

18 hours ago

Vulnerabilities

0
2
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:087248ce97bd2cc1d596c76e403b5662fa1bea3074b9faa8cdb53e787853c1ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:ba7788c1f9918f6c354fb0268b1d019f7418b5f202c66b2101aa123e745f5304
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/netbox@sha256:67d0aac71c5fb9a81902396d24d96526af0133b7c64c56b4d942de10e0809515
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:4ea21402b90b69827402bf5711a91afda09ce4e0a84969ee00f756239015d7a4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/netbox@sha256:d104d7b968d981f36501523cc3d0bfad5f98676c14d377ac92ccb5609e945b19
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:013f49d674501ded140da6bb02edbed5703c31fb15e7ce2b21ad7a836833f04e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:1a1eb7c96ba928183fbf26a1d5f1036402aba2c52848f9955bc479f2ed417ed4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:59ec58632ceda9d269590e6cc667983610126d26c4484ca6916a4a695cecd55e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:88a5b94b9ff908a3909b587d76e2b8b2591a8f86d632f9a434e0890cf061f733
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:f5a8980f6de4b453d6d9bc92039f15f5d0ecac262eb182626319740217928bca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:a57cb89f1790897b30751c9e8145ea6fbc0161d640e50380b67b227f986e9941
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:ad589fd346567611e8649aad6329e989540e9f376d045aee954d722c33570f71
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:9ca596bb0e3f31b66241e4dfb103393ac4e35d8d464709c7549451ce5a0789ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:3425c8c2ca8f4e32fa50f09b466819e705fd3e9b04a2e7630d020d8811b52513
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:8c67d55217bd188d50e5f660405ae171e71e8eb94d0fb147cb13ea6d91b929bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:9e52b091e835684f59d15fbd6ceeb44e39653079006979c35ed62343a8d28d31
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:6e80dec2d528aa92ff99c4186810a7e00305dd8ab235ec1d01ba91dcce581dc0