dhi.io/scout-cli
1, 1-debian, 1-debian13, 1.23, 1.23-debian, 1.23-debian13, 1.23.1, 1.23.1-debian, 1.23.1-debian13
sha256:08e40f1abfebe5ada57145660a8b3c18eddec326c3f84790f3cd47407cd45aa1
Manifest digest:sha256:7249d70da9cf9fc591d07f4f7721d85661e1258b1445dfd8003d6d85bfea5936
Size
55.24 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/scout-cli:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/scout-cli:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/scout-cli@sha256:2032ab49ace03008c957174623fc524fee2d69d86e01a77fc7de642b9e24a8b3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/scout-cli@sha256:9e7303827f5ef66175402a11e0481396fa171656931523c4fb2090d375ad0086 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/scout-cli@sha256:df14fb2dc370b89bc1abff50065de31a588543db88659cfb9b6463b286f5134e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/scout-cli@sha256:b71c7302024ea9631948deb143066b34021057790f440c34614cdcbdc52669a1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/scout-cli@sha256:07026b050b605d421036f2bd78f88f613b010d6c20f01d4a3e407c21a60aba45 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/scout-cli@sha256:b08f037dc3a3b58ee49a59d0ec06f42582012109069cbd2d3bd0c02578a18ec9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/scout-cli@sha256:3f83e59b0069aeb4adb1b08f0bb29a83ac8fd5e54e5882c0a13035da72962044 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/scout-cli@sha256:67954aae41276bccfc1d371019e4cc82954e01cba0c3750974736c500a7b27f2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/scout-cli@sha256:6ee80fda22bae78a0519f76f308483a866be1012b0c23eab1e51d21e47baf426 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/scout-cli@sha256:6d11914e6fb216edce50b8e126b8c4f2a7520e0c64f1e9eafa3888302f94d71b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/scout-cli@sha256:e8901422ff6e12cfeffc88c83fd89ada18728fcb75451dcb0eb01a1de9612751 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/scout-cli@sha256:8eb25b8efc823a1ae11e2c4d159727d8173e56ad89b688dd742a5735201edec5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/scout-cli@sha256:2cfde27ef948a7f8571013707f280b73b70597bf4bb68542c0c67046dfbd9ce2 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/scout-cli@sha256:c0a53be4b18842588650e94a7fd8046a3141c36d6d9a67d53208baf553d9c2d2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/scout-cli@sha256:ade8cde0c77d4d9fe163f9bf1484a1f31b8fbb449c48aa44252b840b9b83ff82 |