Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.9, 1.14.9-debian, 1.14.9-debian13

Index digest:

sha256:7a31329fe09b94205a91b13e451cdcb8a7c8f4f16a8f222120c84640795bcd7d

Manifest digest:

sha256:048ea3f1857d594dff15cbfb7480121d50ea2e6cc4ed21487ac0448a67e8f02e

Size

59.86 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:3ecdb26216f0c97a9a6bace3016ff617b9c5cb9d5cad85e6cd90af0b2b621904
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:068b49b4bfc2f45efe563583cd6cadb542a4e9500f503bf3837e08de0e73fce6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:973243fe928d7ae0a10807ed7f600bf7ca08d941e5ace433599544fbfdb9d038
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:676d045c2372bd600c51d8dead28e894f738c414e40803a908ab2c161c000ca5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:d18ce430b180b9203fb81f96aba2b89a12619dcd373036de73a56e24be75fb22
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:5ed72b6ef09855d3187da3b0765d474760435654ad5c51a8e679fe31b02a854e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:df38479229a59553ade246e1ba91295451fd4b18a242cf7a78ea20f03c39b8d2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:5a81ca2f28ac5306168a99e861a7494c85b01711e59ed4d8a99d95d2811e4e94
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:d91a01c603512de33d41d00bc10548a3da929f85297370b97b978d7b96e4a8a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:a543187129a978cb8afc875ee4187d7f0181c3675fabffc103679a3a9a3d03db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:4304be5843abefcbb6d7e015f3c4f38ce419270edb043da69b847c980f0d2865
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:a3c2fd90ebbc3b96684676ef282623635555f768de174641c640788956881b7d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:d6cc6cc707bbbf932eab49da7e588cf93ffe6df0e800738c02a960029456064c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:410b63cbd9a3056ddcfc655cf94848a4e0ecbdb0448764a32a59ff7cbd556902
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:ca4d96cd5d487348f7665d2c82f21cb790546677fd9458be86427e165b940947