dhi.io/scout-cli
1-debian-fips, 1-debian13-fips, 1-fips, 1.23-debian-fips, 1.23-debian13-fips, 1.23-fips, 1.23.1-debian-fips, 1.23.1-debian13-fips, 1.23.1-fips
sha256:fed190fc00ebd1fd2e7bcf6b0d6a88f3020d7ca8c6531bea688c457f7a4f7ba1
Manifest digest:sha256:82763f4cc04146988b2100183b5e80255c39ca64c8904bf2e48c63c0dd873aab
Size
63.42 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/scout-cli:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/scout-cli:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/scout-cli@sha256:73813581945d0667f8860ecac0d5f83d94c7dbd93e0aa58b51c553cbfc50d520 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/scout-cli@sha256:850c4a785891f3086f6e9703caf761c4592b60c5840fee61ee726bdaa8fcea61 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/scout-cli@sha256:48ac70bcd413951fab67e84e3642ab78b7ce495f96380b66f5989a5aaaf025b6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/scout-cli@sha256:cd1abbac6e3b71f3d822054a1c8d24d499f823efab07bdda74ba014ef48a6204 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/scout-cli@sha256:e858059d92c82ab54a630b0290e6485af3254a3ef4d6837d170a436cdf3bcc4c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/scout-cli@sha256:9cf7d9ba7403389c2b890fe58d858bb61d47c4863dc34c4161c8d11771e2fa4b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/scout-cli@sha256:4c0b1942e7ef5fd890149c99eeffb181d5b22fbf0bceb2e2798d1ec998788fd5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/scout-cli@sha256:7132285234832f1ff4023e3ddc431cc718bec61d1ad74081f4232cef9b60153e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/scout-cli@sha256:30ed0ec96a5329cff6ad2e9d954f1f40fad319d2133ae28105f2cc4cca33a873 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/scout-cli@sha256:a04a5ac30a4a9ca34f60261910c54f105b4c9b27cae512c463ff9dec0ef437a6 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/scout-cli@sha256:e2fb8bad062aaeecb01a29a2cdc0e2337c8b497df5361c0b046ddabe3555b0ad |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/scout-cli@sha256:a14da6696bed003825f661b8935d33a338062c6a8dbdc5c402cec85866e1f12d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/scout-cli@sha256:c7d4eac8eb203fa4ec7c9461dc564e533d0146fe11beeffeb5076a5083c475dd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/scout-cli@sha256:ef61936ec516f5fd547b8de3cc87dfe34c8992c6e105e90ae846ffd995b64235 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/scout-cli@sha256:139f1d6210d911b9577397841a3a6046e046d7ac47dfdca9a305e7b395dd8343 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/scout-cli@sha256:6f2577453395e72cae8431aed74f6d71a3dcb4b958e419a18a442af821a16f6f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/scout-cli@sha256:5ad1da2cace9ad09eb8cfc32d95a6889fcbd70ef609f4c128c612ec3b18c48ab |