dhi.io/netbox
4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.2-debian-fips, 4.7.2-debian13-fips, 4.7.2-fips
sha256:667fb18e1a47c2897f28a3f440f4676bc28a83f1539a910ec777f84a96107050
Manifest digest:sha256:c64937bb7067d498ea6d456792a47462ab84604f5dba6a33dff63d86b2315b8d
Size
122.16 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/netbox:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/netbox:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/netbox@sha256:7b3bcd1599b9182330a29374530cd24103295e58400397580879be9f6796fd3e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/netbox@sha256:d0874c8fcd84c66ee59ba82405187458ceb2c2a1ea75c4042bf1823615669b7f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/netbox@sha256:01e171dcaf9ba4b06048fa5a45c6675f9d922e0b0e563a8386107f3d0d51b33a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/netbox@sha256:0b572b7d9de25bb9efe4b3f35358cd8cb0ba176f2f454c56b3a14c774cb87942 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/netbox@sha256:d190958a3cf2ddf8302b9602d0a6178cd059da12c05f00fe8a340bfeb9d32bc8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/netbox@sha256:8c8c5953b07ed72ce75a17ab10716b13c9d1a4a557fbb1cfb504579ab27ba708 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/netbox@sha256:5b6d5ea4078c03645f56747e32e92a47492f8c5e2d5ac9b6a6406a11577d463b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/netbox@sha256:f0178d291de4637f5cf6294fc19310761708b9e572c0c5fa2efbe6098bbe0603 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/netbox@sha256:ed60edc5957bdbdc21f0f2cb5be923f28f42c939bc0216242deb24398072b3d1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/netbox@sha256:d16263b5b47fa704ecfd8c9b23df85caf5b0c8532b7e6e5265519b9d9f6c20a9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/netbox@sha256:83d8bd0c4f5489fca55530c765e47ddd2f66920506479b4ad6c992946e416638 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/netbox@sha256:8c9fa2c541ecc3d8357167a396df9b6f27acc114dd24a96a32848453532ed9e8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/netbox@sha256:13df146416b69d62b955cd60e30bff4d9270c926764645a9342099b8bd35c38b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/netbox@sha256:4bfd9516c2d197c5b7ec9e9c134e8e43ca7c6447b96fca74ce05098618136d0f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/netbox@sha256:05ccca21f05c057806e27c7ffa6cbc97039069cf0b086d3344f9d36b27e34de6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/netbox@sha256:eb98ac1239500049e7f3a12881720cd39fdca2c2ce737914f7cb432391e2abd5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/netbox@sha256:112230af39b6ae8d11c5a35559c34a5e85cd943a23347448fcfeed442449e115 |