Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.13-alpine, 1.13-alpine3.24, 1.13.6-alpine, 1.13.6-alpine3.24

Index digest:

sha256:62371eeae36fd4c46f9f54abebf6acd54171f56848e0124fc72df8f120f1e733

Manifest digest:

sha256:395fd6f8d596c419f066c9e2528b8b9deea2dbe1af6ea684ebc893d0a407beb2

Size

381.25 MB

Last pushed

6 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:188beb07b29538b75654725f8558180096dbbd3b03d95e53d199fa5d395378bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:b42424108d8b867786a8147c601a2c7cf5f45753174e923641203de410c288f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:8fc2dec294456fef46de2ce1fb65f2566bb7d7b89132bcd0cd4216e9ecebf611
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:b835b09efebd211b1ccf5d3c0a9d9920ec4604871b87fcc984ee72a14e8acdf5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:d51d5314ebbf1cb0fbf2a4dd4c442bd77713105e7450db6da2854a55dc2a0c9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:708d4aae0116170725821dd70349c4d382d61b2e1e407826d45e4ecd0171f3f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:55928e42cd7c3221fc28c685e7c8a62434205bd9dfbb7bbf5717b5037c796c2a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:ba7395f0452853f4df7e52678c40c8b49ed87ec62330fa4ee6b9220c7dfea0fb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:87240141035556cd7605b4f4005e5609943790390705d8a13668ed42116d0b26
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:d6d3037a020f9b65cb17f9d6a6c136f1794165ec2e92dc040e641eadb764c3ec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:66f977ed761f2cac276ffba1d38dab7cdd8550fe6e395f411ed1f31256f470cc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:b501a6377244f85cee84b5f434452f410cdd68fe0b4a24059116feb7d5739be7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:c2c034fd09c6406d9af8061308b53dc0a2743964f8a0df2e2c1d9860557f1ba9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:c58b42600ab7d0d7cafda9ef4db004b409236de4dfc52b8abf8c0cceef59c7bb