dhi.io/openmetadata
1-alpine, 1-alpine3.24, 1.13-alpine, 1.13-alpine3.24, 1.13.6-alpine, 1.13.6-alpine3.24
sha256:dee7f0c4a796710b0d6be2ccc26ab61fc121c8841905f0501149106daa2cc383
Manifest digest:sha256:18102c91ef54cd43e0bce740e8f3e797da7bea23c2d0227607a59088e9ada303
Size
381.25 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openmetadata:1-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openmetadata:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openmetadata@sha256:88c53658f52bc5f3081131da1ae654983363d30233419905f17477bc246c615e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openmetadata@sha256:6909044e2864a05840ececc33b00c65b871fb43529d00facfed9738ad4703bd8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openmetadata@sha256:b2103b8bdba85944d385daa5a95163536ac591600fd744155065ca63079692bf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openmetadata@sha256:8472e1f8423108cd3e85910db47070cd27109d71f892fc3edc16de9aba4778a5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openmetadata@sha256:01402c0baf17d330f30cc97c5f9b73ea6a3f0d4037181cbe73ed36d7a20699ba |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openmetadata@sha256:24cdb85aa51794208225f0f2f8527cb4cca88615036529178bd9c0e7ecb81ca9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openmetadata@sha256:2d8211de1d419a1ea2769ef2ee50245c736e0b829363fd668dce65c702b339b0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openmetadata@sha256:d66c7946432918121d1d23ee33ec525d9ca8dcfd13423be6fb54f9ab7fa4758c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openmetadata@sha256:b2c2e2112223b0387b4d60202284b2333b6128400127c3f1a5f3579a9fa1e945 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openmetadata@sha256:b908056c4ee412b400b21b24ac02c7d1d139557c81311a7da16430b3544b47ed |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openmetadata@sha256:867a51bbbfcfa9f4d5fa1ac87e99151861d74c23e85a4b9fed52bdc892d47925 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openmetadata@sha256:dc87b57fe7a07425e4162e56be0d072525600fd1c04097740ba612b8c897811c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openmetadata@sha256:81231d276ab66a9f49f60a1ab4646ace61ad79a733be084b4072ea12366669f4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openmetadata@sha256:f5caf997fb977d05eeb1b4ec6b8344bd8f62c3ba1485858c1215f1dbd0e36541 |