Sign inSign up
Snapshot Controller

dhi.io/snapshot-controller

Snapshot Controller 8.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8.3-debian-fips, 8.3-debian13-fips, 8.3-fips, 8.3.0-debian-fips, 8.3.0-debian13-fips, 8.3.0-fips

Index digest:

sha256:69e5da08a228bc3172d8f5ec2067f3996e0235f1c49e2c4a585d02d54f2dd45e

Manifest digest:

sha256:b099f405b3e57c85ff00d1fee05a20fdafd9edab0133b5658feef35e687e1edc

Size

21.26 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/snapshot-controller:8.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/snapshot-controller:8.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/snapshot-controller@sha256:b280afcfd63d04abe88941122a1329335bfca6e18a9a412b04ba0226fcba7470
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/snapshot-controller@sha256:73d15f7ac25341e6554bf45ba6184d7e2e9a9dd7397de907fa70f41e021b6a63
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/snapshot-controller@sha256:0469bc4a3af9e779ca9b3b9cae5e39d5f6e5950d53670b4b0b1d133b838c84eb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/snapshot-controller@sha256:b0df1abda26afc0f912b802e0383c5f3517472c3e42f7d2576b105aa666314fb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/snapshot-controller@sha256:8b6971345c4836844a53c7d453843aabfea5a0c65d3dde964361bb5c0a8bcf02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/snapshot-controller@sha256:268b995cbcba5b2d8fd45f5505999b07bdbc149a7557d4eb5a284a1dbf2ae113
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/snapshot-controller@sha256:ab888c6abd444dbd778fb7c1db5ee6ea46deb348b86b0263c1771b84725847bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/snapshot-controller@sha256:ee3bea5cf3acf0350c60a58d6447bcb3ed78883e2a96a1729591f1f16f959c3a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/snapshot-controller@sha256:e6534cb7b45148a0b355aaf81272417be2802106d67df4cf770a19d668779423
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/snapshot-controller@sha256:f55cb998ced0ccc820597670fa96925e8e82427051e4ff2f30f438512f86c445
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/snapshot-controller@sha256:45964be9009e4210c64bd2bbd9f1b4a9eaff283e936be6d37e20d4f90285f2f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/snapshot-controller@sha256:45aed3efd75bc631ceba7ad086464a6df3a6c35e813ced1c914584c504798d54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/snapshot-controller@sha256:d5878b3d062e6a53625e5a5d5dba2b77af40f1b6c5960ba47578ed7fb2862b28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/snapshot-controller@sha256:7ef25db3580e58b78fc118ca57e1592e36ffb9373eebedf8e22a5d25a13739d6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/snapshot-controller@sha256:9e5bd42ea285704f0f3195b7ffd831f6c736a9e758afe1a1d664207c589f4185
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/snapshot-controller@sha256:f02e9cdf54ed60aa7dd5d112fd1f54881b6b0649b83e42995903e164549b4c29
SPDX SBOMhttps://spdx.dev/Documentdhi.io/snapshot-controller@sha256:4129684b84941ca5a7879619971e3f01a8bca5ef855ba96f42fc36a705e33b10