Sign inSign up
Apache NiFi

dhi.io/nifi

Apache NiFi 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.12, 2.12-debian, 2.12-debian13, 2.12.0, 2.12.0-debian, 2.12.0-debian13

Index digest:

sha256:0a3b886aba0733ad96f42fe2cb0d7d85684a7e98eb3a0e0ce64ddac85926c821

Manifest digest:

sha256:0d5d307f054e1a563e9f364ce9dacdef8fad372ec3ff48bab8d88efd21f0e1d0

Size

1.20 GB

Last pushed

14 hours ago

Vulnerabilities

0
9
14
2
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nifi:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nifi:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nifi@sha256:4a164c1aa314ccbd4952e647b90f421348759239b0ef6a4f2771924d65b993e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nifi@sha256:42658f2afeb502af3902d9e44e972d7445baf43673dd6c356548c26f629d451a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nifi@sha256:683047075b0e23c7ab1f41db983ac043cae00e0caa4b8b7c7201eea6a8c4fd98
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nifi@sha256:95ce84c16144e603e58cbc498a266e664e40c4342545d61c3a0cf5f35e85b4bb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nifi@sha256:14ddd8b41c6746025e9e9087372eeb6be4a4d5ff7b48ef28b0742de80f8ee3b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nifi@sha256:688d72d0dd58dee987e6542dfb095d59c82a85c6974d64bf462a49988c57d664
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nifi@sha256:952b73d39bcdc254454a1d2cf050a59d43277496763292e4d90e46b0abdb6c36
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nifi@sha256:98832ed3a6ba3ac18275ae8d52cfce2f58e6cffe3516812d635e72b1fea64032
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nifi@sha256:a1167ca13863f1a2218ae6685bcaa513c30648b0a53095d88e571aecedbff8b1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nifi@sha256:09d312ead21aac37772d4475494af9d826494d634863dcb06bd5bac4249d7434
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nifi@sha256:8d381ff36d95efa4aedf8a659fddd26c5dfce5e192235ccc031ac0f03ff73a3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nifi@sha256:15f19b863369a619bef67e5801703173bdc5cc99f29935293bd17d85012fb23a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nifi@sha256:4675ef3182c2c0c7bd5073b0d4bf0987331b8f6d69ae84ecb655e67b6f827f9a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nifi@sha256:7e065f06e073b2ee99a1720a1f3eabaf6de5551c2c5d575d8b5b496a256bf9de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nifi@sha256:6721667cf062d07fe42687ac624f112537444669d71349d8093a6ee770c6aa00