Sign inSign up
Snapshot Controller

dhi.io/snapshot-controller

Snapshot Controller 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev

Index digest:

sha256:dd1594651d3025ef93d63958c2b10f43f210841e0ef34a80b1212d767d09ff93

Manifest digest:

sha256:beea733bd0e83575147f49ee7d732d829e6895aa66bd73e35f6f37af79b92b56

Size

56.11 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snapshot-controller:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snapshot-controller:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snapshot-controller@sha256:124c0622fd497c7cafba047d758a5d04faef247b2434d56b7e02294cc073b57d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snapshot-controller@sha256:e3686f8df4d78e63b59c8858222336c911d0bf408b2e55e817aeb1d5cc927e3a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snapshot-controller@sha256:3cd3a88a4de6d937b48862121d985a205b356271574f7fc7a445313eca75a00a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snapshot-controller@sha256:f9f7f8de4bb453de13fe74f10287bc174b098dece7dccd74a1915618e2b61d72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snapshot-controller@sha256:65f1a0517dd77845cf37b8ab11ce57bb93be731a7db06027e0ff68ce6d79a3af
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snapshot-controller@sha256:ac3337c0e458034df3529e10665b948c3784cc37c2ca9cd3c2b4d7a2e6ecfdbb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snapshot-controller@sha256:a624c8f58cbeb9c7466287122757d674bf0e8733479ecd00838863b74a7a976b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snapshot-controller@sha256:2008804d70b8d85527ceba70a7e0623dfc6e01cd1e020dfa1dd45aa54279ae89
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snapshot-controller@sha256:fe89c8c57b4eb9bf4ce834dae169e00140b4d604fdf51e6082363ecd11fdb348
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snapshot-controller@sha256:f1fd49851cce4bcf708aa704acf84c9c0b3811d9fcda75848942dae65e61aafa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snapshot-controller@sha256:9200cf359e8dff3e9d75c98d1a43fadf0cdc9b9c5c406a1c083df4b592d053dd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snapshot-controller@sha256:30853d242f98d649e6e650cf4a097f705bf9bc77a69aaeafc710eab33b0dfb33
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snapshot-controller@sha256:0281f4563171221c112aceb7a9a351672d1e5c37cf4fe86f3a91348e26a8143d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snapshot-controller@sha256:6110c1266c43f584c34a25e353742ed3f2525d6d78892bc4d42637a728f6b058
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snapshot-controller@sha256:758a6493f4e9f5b6d13125813da3d4bcef1084805253ba65a0cb9be446a15bfd