Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips, 2-alpine3.24-fips, 2.0-alpine-fips, 2.0-alpine3.24-fips, 2.0.4-alpine-fips, 2.0.4-alpine3.24-fips

Index digest:

sha256:33ee1a6b9487a16e004f010ff06a5f71c69d0d6d00650e9d8c7857585bfc68fb

Manifest digest:

sha256:38da16be8f37e5ac25efa7722e844e753d28b30b193959a15260f7d858e7fcc2

Size

428.92 MB

Last pushed

23 hours ago

Vulnerabilities

0
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:2cc76e9159848c0979a8d6a8c5428aa5ac189175f12be8ebb087d7027c72953f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:98918d5527774499e2b596a7d2391c52545ac45d4a1843e98bd80e68c981fd7e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:79d6933711d74665b24e9d09c570ed38c479c70b54dfa2f36ec9060623fe09d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:d02207492c210586df38c9142e61999b810f4f03e0ad19fc9b1f4841cec7ce79
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:8ad2edd78195ce0ac6f6c270c2c6848e1b8ff02fc0b62129e922f00da6b25e86
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:7be622d196078637b7ef4972c3b6524d44c83281b134eb66f91f67b11ff776b4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:7c083531ef8875dab2484c604d16a369c5bdbb9476e5926226d8c0b7df4cd005
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:85af13f0fb566f3d9c235216c710012ecfb25959e0bd2708e683d58ccc53a739
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:d0378e5184cf9b5ecb4526532e515fc8b2b101b9067dccef048890bb8f963724
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:cec6e4b8a9d414d3f3392fe2ab83706048d8fcd254938d06d8889d0e660723e4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:8d6aba7a2535cc0cf643c39a737c987f6e9a9838c51f0836648d56e660fcc855
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:f43be6d61254cc6d8c6f2f5e37b1e2fe64fad005b5e7f5f6103069656f6dad48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:292adcc77afa7654f3e352b49e86465a23e4521b3887fcb9efd55a9641c16509
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:0f34c0c8cc4eb7d565055ab6675ff903ae79032ec64090ba0e1ab8f344085f86
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:ab27114bc41f44ba623d63268b7621554f09d2a63a6a125eb6ab1b7402c10201
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:8c3661491d2538dff3e59fdf7e92e222dbc8c688abf557f7acea9c8cc612cf31