Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.2-debian-fips-dev, 4.7.2-debian13-fips-dev, 4.7.2-fips-dev

Index digest:

sha256:35a9fed5cedd48895c4e13f5de64640cfa2dc384ef19a39a6296f9deb4d20f4f

Manifest digest:

sha256:104f3ea33b54a919e1c68ddf4f6dc1b560c5812d097805e26b5a6baa068e09b8

Size

130.37 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:c62bf4ba960bfd2710f94d48d1e35a98ede2548cccfe5dc8d392a75f4334d3e6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:739fc078bd8f68834c563e1c6b59846522ed8d01e8710b18a2a350068b745edb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/netbox@sha256:ac955f6a2ecad7a3107a409f1f7d22025f6aa27aca9e9edb97d901a6e28e346a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:7779ccc55b80b26e2e484f16fefaabaa699afcb1d9143a399721bf2534b9fad1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/netbox@sha256:902613db9f001feac8292fa87ad6f22c3fa33bd8033f02d7cf466d49396342a2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:97d13b9cf4459489436d163373deb61fa76bbb16c37ea30e35fa56f1d3e7987c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:a2cf3e48d6fe0f0a3689e56af233bed1fa28122def4e269fbdefd724a9e18036
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:07f866d8b8f77904710ec9eeb97989562bbe7ca724c2452be9d899588c291593
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:02acb0bb5c0df0733868dfab2ac02df82db6cbeaaa2c0879e7d9f8d6fa1e6de2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:678b177c3693342d77f94b5914a5b33fb3fae5ee03331f06fe29f5a5ca097c9c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:361073b9fda6a828e621f5bff6dd19496b76ece1e1755c5f2c335e6099d74b0a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:f3123fb99c53b1db9d6b9269f0fab56c003549d08fb866b687489c349db18ef5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:f211511fdad9c1de36d6f91717aed7ed0ee6b938460ec58bcb265818332f4aa5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:fb52c5fad0155a89f6a42434fb774164502508bd74c4383bd40d30b56b71992d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:931e7e0114931315633c3476d3320c30619170dc5e4a10803c60fce1c61868f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:3d3c26398286e2e0109e28623e34083db37b8cc15845e207f197bae689de1352
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:e2e6f03d71e122e2cbeb42e5489f37ef9cfc4e9fc4780db7c0ea103f897a5ecd