dhi.io/netbox
4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.2-debian-fips, 4.7.2-debian13-fips, 4.7.2-fips
sha256:b4778e5a76245da45e36932d85aee5fdf5b49d08ef21d8b0b4d00f0af8d16224
Manifest digest:sha256:2d8deb56a40e73aabc61a93948ddbeb3fbbe79a43820165f39a7787c8186af92
Size
122.14 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/netbox:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/netbox:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/netbox@sha256:0b70315d4779fc8c67258d2b98f4920eb36b7d0464a4ab62e10ecd942d64faf3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/netbox@sha256:b6dc822576f5d3c14a3c915ab95dcadb3ba1ffdd9909b27ffcca6988366c9413 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/netbox@sha256:29f41fbe93ebcad760081487b00f9e3ed8c93ce70cc96e3516df09e03e747240 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/netbox@sha256:c6d8889f20993126256cefabf3c40e7f3357f1d7021440431daab28c8c8213ce |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/netbox@sha256:f5ee43c69ae30eefb55569d23869f36277ef7f11a812f90597e59aa1ee2bb90c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/netbox@sha256:6327e8f60b4c695c8565a068729fbea05802a66d102296ca9d383914c560c588 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/netbox@sha256:447f391b5c60df4b62f0b52cc48551c0f059d1353cf12760d2efc968aa6cb53d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/netbox@sha256:18e004b242ae057e50d02c07cf1273cdb0ef47bb8e649cee5f97502e69137d52 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/netbox@sha256:84ea88fab3ea4ddca8affa3feb509f7ece6d3790cce4d943072dab1685910d3f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/netbox@sha256:2971c57a626b58d02342ee669ec938d886cf840ff47f9509d57f7404de8d5576 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/netbox@sha256:9102105f1b76af9f58fa3b492f8d08bb94e125ede283fd531c37068509f0db6b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/netbox@sha256:31568b23970559e18394e91c3ae7a38f25e4cdf2fa228e100c14068c3dab5d9e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/netbox@sha256:44d2c8bbc54244792ef32c1094c812b07ef08e21a5a94f3b94c6269c5691ff79 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/netbox@sha256:66d1c29549eb4ff9b58b91a35dd2f3ff69c81d9ec92bd7605fb2e44edc0338eb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/netbox@sha256:c735988dfc7dab2106f36f88b6af0ca1e015a93058b23fbb39cbdb0e71860b35 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/netbox@sha256:fbbe9911d8bd00f15d2822cc69873016bcd3a00de510c80b6a16fbf6706c8aa6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/netbox@sha256:7ef963a4d29d6f09328a9684aa5c08860683fbc8af76489adee4d21512a09d04 |