Sign inSign up
Snapshot Controller

dhi.io/snapshot-controller

Snapshot Controller 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.6-debian-dev, 8.6-debian13-dev, 8.6-dev, 8.6.0-debian-dev, 8.6.0-debian13-dev, 8.6.0-dev

Index digest:

sha256:e64acf18929861b3209feb3ff95d56b937380e3064a4503016251d6d0e1867c8

Manifest digest:

sha256:d52bd85d75d0799e697c0389a0b90230b5811cbd7936ea00884631cd4128ff1a

Size

56.13 MB

Last pushed

1 day ago

Vulnerabilities

0
2
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snapshot-controller:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snapshot-controller:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snapshot-controller@sha256:9a3ab808cd3a649485e5c6dbd52cfd560846baf2c4f942526d5d0a2bd097aca6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snapshot-controller@sha256:c3bd2dfdde8fd330ac234f97bbd6449d5ce6603d4ccdf81944481b90db639b4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snapshot-controller@sha256:c793d919fe728dfdd8a2988efab20239e39bdb534787bb7bef45d1f607b2295e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snapshot-controller@sha256:78d6374a06ae7d8e6f75a6422d5be293ed67bd963e25ba4884b52975da172205
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snapshot-controller@sha256:b5b355538600b932ec2ac755476339331d6e0dd3e445f811a493c51b0693c7b8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snapshot-controller@sha256:5caa14c58b87b1f1cc4e7af8a35b1dc7f6f1e5264ec157ce36b7719cb8eda2d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snapshot-controller@sha256:46d1e4fdf1360364a30932665d951c0d851d92822548d142c7f093834658706e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snapshot-controller@sha256:ebb3eb47d6d9085de3be24464b88010c70f2100c554210ea83eb6e0aefc91821
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snapshot-controller@sha256:8eea824ac6f706ebbff9d7a84f3ce7bb106cb7c4d4ea92dde6a0cbe944a60e90
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snapshot-controller@sha256:bae2c9962600339dc2afad8b687789e765763cfd859dbb48d252b8ff62a600b0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snapshot-controller@sha256:1acbb6a5d9b143974094ebfe3baa4d2375b5f225f918f22c83670ce8259cf6af
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snapshot-controller@sha256:a55e1759556df28ac8fdde509203015b0e4fc5af5a1ff87a78f6d6091130fa0c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snapshot-controller@sha256:bfe1937c4f8536ada215d006b83ca142e8be3ba84c6cf891406003ed23463088
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snapshot-controller@sha256:a3cb810f54c9a64a6282907c1e3ccd92b05b14b888322cd5beb14c657da693a7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snapshot-controller@sha256:51ebb067a014937a7cee662a79991d3018e4eceb6ebb76209ac90acdf65d7316