Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.0-alpine-dev, 2.0-alpine3.24-dev, 2.0.2-alpine-dev, 2.0.2-alpine3.24-dev

Index digest:

sha256:27cb1bef25c774149987a700b3efa30b49678f7e45a5ba72051ad790ff97e8e8

Manifest digest:

sha256:d3f2fb390a93c42c7936e9d46e26d3c0643f90c777e438e6f4bafd557b3d1d91

Size

419.41 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:e24fea906a6c36d0ec0b2d0b220f4d777b7f8aaea861b6319a54abc5e3716c52
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:bf6328d95fc795c7789dac17908ce7395e0263dc572d898c7fac2334a54035b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:beec91c7c050b34d3f3977d614013ae612ff9466063b5080a669ffa989f6c71c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:11f7bad0363349809eb502c17078a5126c7d013e3adfc9dba0dcffd7d768c53f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:adc7b0b8a844495a1a4ac15bd2137de657b3e3bf8e8b97bc9b7b64c931e4980b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:53d7dd475b4eb293acca1b299dd4ef14bd7ee606122ce5e885a048479586dab8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:f9df2e1d63a8cdb436222059d2d1356a6540e898f8410cda3a84a5a834d5f635
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:c45fcc221aa0e50f13417c2371ce2acdc703e1ebcb6aa0fd7daf7516d8b5a874
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:29f54a7aaed0dd4c71fae83756c60c3722d8f474d0685b5651dddfda8aa1cf2b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:02036696dec7115030cc75ac237df516b2a7b47ddb180b3561f9d7ee3848a5c3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:a052226b43cee4e534ad1f4cb41dcead204c0d8291dd3611f73a97acc04f2a55
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:5d8f5952f5b1573f2f58308bf506f29528a6ead7098337ccc4f9071960f75d0a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:da095d76efdbaee6ed2fadae197a7b7a3a704467ba7a54d498c1ca1ef9656425
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:e32022e165250400c2df7a561e805ec356ce30250d270c7a740087f31d81b7e5