Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.13-alpine, 1.13-alpine3.24, 1.13.6-alpine, 1.13.6-alpine3.24

Index digest:

sha256:dee7f0c4a796710b0d6be2ccc26ab61fc121c8841905f0501149106daa2cc383

Manifest digest:

sha256:18102c91ef54cd43e0bce740e8f3e797da7bea23c2d0227607a59088e9ada303

Size

381.25 MB

Last pushed

2 days ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:88c53658f52bc5f3081131da1ae654983363d30233419905f17477bc246c615e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:6909044e2864a05840ececc33b00c65b871fb43529d00facfed9738ad4703bd8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:b2103b8bdba85944d385daa5a95163536ac591600fd744155065ca63079692bf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:8472e1f8423108cd3e85910db47070cd27109d71f892fc3edc16de9aba4778a5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:01402c0baf17d330f30cc97c5f9b73ea6a3f0d4037181cbe73ed36d7a20699ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:24cdb85aa51794208225f0f2f8527cb4cca88615036529178bd9c0e7ecb81ca9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:2d8211de1d419a1ea2769ef2ee50245c736e0b829363fd668dce65c702b339b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:d66c7946432918121d1d23ee33ec525d9ca8dcfd13423be6fb54f9ab7fa4758c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:b2c2e2112223b0387b4d60202284b2333b6128400127c3f1a5f3579a9fa1e945
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:b908056c4ee412b400b21b24ac02c7d1d139557c81311a7da16430b3544b47ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:867a51bbbfcfa9f4d5fa1ac87e99151861d74c23e85a4b9fed52bdc892d47925
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:dc87b57fe7a07425e4162e56be0d072525600fd1c04097740ba612b8c897811c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:81231d276ab66a9f49f60a1ab4646ace61ad79a733be084b4072ea12366669f4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:f5caf997fb977d05eeb1b4ec6b8344bd8f62c3ba1485858c1215f1dbd0e36541