Sign inSign up
Pinniped CLI

dhi.io/pinniped-cli

Pinniped CLI 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.47, 0.47-debian, 0.47-debian13, 0.47.0, 0.47.0-debian, 0.47.0-debian13

Index digest:

sha256:61568cc923c25ace73ac68a565fff86bb0e1b4621236b83c79354f5af9bf9489

Manifest digest:

sha256:a6a6566b5494ce8337a2a59600d6f21c602e8e0941aba5201e3e9c95527364be

Size

17.21 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pinniped-cli:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pinniped-cli:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pinniped-cli@sha256:2cce0657b37f76cd59b8c800eb09cf7901482df8c42aede0db0f10f7d5c601b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pinniped-cli@sha256:d8af43b44b66144019bccf3cfff16375565eedc91a12f829801a8e0abd9f6dec
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pinniped-cli@sha256:210d11e29c7b39fab0e390a6a46979994faadfb8f56cd6251a7f619c323a9e1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pinniped-cli@sha256:76a86165277a9b8a2d57e76778060243d38e0eb61588066cf35f8b4de22f7f1b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pinniped-cli@sha256:6a5544235aaecd60a74790b2545f0cf0e505dc5e5da3b28dec47404c8ace091b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pinniped-cli@sha256:0abefb6b0f7b73486212cca33fe89b4153cfc72d3254dbd6a549f624964c1a6c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pinniped-cli@sha256:58277adab61a0402f07bee13756acdfbee11951575f1d7369ebedc379ffd89c3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pinniped-cli@sha256:0167c52d595ee3461a88d60ad4c408e203947b64a67bb093af777ee222d1de03
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pinniped-cli@sha256:67c97f34f9e90fc6584ec4398610a170101ef86b32ef50d02ac57088f3973126
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pinniped-cli@sha256:3f6b4992202102835292b2768c75cdcf2a8025e3f11e18c794ebd956a0ea3926
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pinniped-cli@sha256:0944e0df0cf25a00844487ae8791b469ae35fc9a6503978d035084b66228d855
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pinniped-cli@sha256:0f27022fc76fd0808bf218f099def304a0d84a36aeae703f3c7ecf499ee2f9b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pinniped-cli@sha256:2e1909383eb606c94f13c91d4e9e6b015ec71f4a3dadbaf239554e852cb56d0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pinniped-cli@sha256:d60a3dfe9e120e4cd67e1ce7b7d0a24e45504e31902481ae91441c5d7fd22fea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pinniped-cli@sha256:942fe5b2aaab884f95f5b9e5213364eac634affecac11b81680025702edf481b