Sign inSign up
Docker Scout CLI

dhi.io/scout-cli

Docker Scout CLI 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.23-debian-fips-dev, 1.23-debian13-fips-dev, 1.23-fips-dev, 1.23.1-debian-fips-dev, 1.23.1-debian13-fips-dev, 1.23.1-fips-dev

Index digest:

sha256:c8bedd783ac6193d844935ab2bfb6aa009673fec6df729ebfea147a05f387d78

Manifest digest:

sha256:76901e4ba773bda7acdf547f576443bd2c90b0d5651d04147374c39a1f948a58

Size

130.33 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
3
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/scout-cli:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/scout-cli:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/scout-cli@sha256:3fd0a3782e75b7cda50836d6c7e46ab17317df7febae35d022b51815b3fdedc4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/scout-cli@sha256:1387b9ee6d1ab6d2228d6d51b87531e0b15a6f27f24b6eeea6949befe9e92de1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/scout-cli@sha256:3b25396caffcee93b8a2b67fdc3e5f6ffe07b16cb51c84884c483e7a95308e4d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/scout-cli@sha256:ed05b65a16eea9e8ded2f010d2ded1336cc9bb347b8fe6250c5f83f73a2f97b6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/scout-cli@sha256:03001269c8e0265b5e2e48452d8e3231d954f0f88be358a8fdef2315406c647d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/scout-cli@sha256:5ff9895116ad6a45336774bb82c473f4fa2a1acdd11c8084daa0ab731135a8cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/scout-cli@sha256:f322dd04fa27e077a48daae94db99dc604fa6209e5bb1c9489646b00891f3e51
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/scout-cli@sha256:3ba02a47ff70854c0807b40a92026fd43e58330d7e5c60a5d69eda873598c65b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/scout-cli@sha256:b55ac87c4794d1a42aead135f890cd818194c594b5e3cab81220d6ce6cefdd6b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/scout-cli@sha256:96348819df69f6578c85da11f398dabb5b13f6aecb116b5b289409a1e59ddeb0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/scout-cli@sha256:74a3e87776552aa64c29435af903539eaa6e6896db3197e780159f35b39eae7d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/scout-cli@sha256:237fb430ad77ec5659a2b56d37cd030e4ea9eca9926e4c58014705d8d7fbc259
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/scout-cli@sha256:65219c359d9aab4193d9dd028df84bc858c7b672e3f5b6d89d3b6c5533577fd0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/scout-cli@sha256:476c5d25e6024e2bb65bc931c666b3399fe364f713f6642a296ce493fa65958c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/scout-cli@sha256:f2607985f9f3b1ebee96ba3153edf5457dba7f58ab5fc7029303e0ad3ccb34e8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/scout-cli@sha256:c875e463a14c29a68948486b2a50124d29f9e6f09504cde8879cfb741d12ee9d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/scout-cli@sha256:c4fd88270021e875dcad1cf7bacf3cdc6c459e4db62567617fcf1bed6bbaa467