Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.9, 1.14.9-debian, 1.14.9-debian13

Index digest:

sha256:2b05b3641c5c2512e0af7e25e654b01512b5e389c0de2259b5fc54632d4e25db

Manifest digest:

sha256:3cb2c8cdf08ac0c0b8057445d7655fd6322938030bf6ff8cd06d3156d55530bc

Size

59.88 MB

Last pushed

7 hours ago

Vulnerabilities

1
5
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:790847467be0e2254d43907c60b6614fff7c1176d5ce7f73aca2d3550a5f0c61
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:5d7ad1571d253e193324a649456e737369549079fcb849e557d6665c3ffb6497
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:b2eebb0a162f595e4325f60fa8d6f99d5e5648e002881abe46d3993d624a3777
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:229bea8992734e233adcbd31c11f6f3bdbc1ab0fdfa1f4b0a53d08c920aaa1ab
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:16363dda74601da097349f05dcd1736b1ade2253eba683cd44f8064569141bcb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:9ee3cb7cbd8b7bc2a63a4e36a989b4e491bb1561c9485cd1cd0abcac54a06643
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:fe881c0f22b8bd5f8386c7db9afddca3c0f91c7301682cd201120d4161fb421b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:08639b26d962a42492858c8a1762ac1bcc4e9b7c361c4026c65ae77b2c06cc16
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:aaaa6c225d193fb778e5864f7ac78116a753e72174b2f727c4db1feaa74f216c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:d70af2e3a45ca73951edf50a92806622f65cbe516280adc938f8a9eafa2ac478
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:e6c01293cd47c3114f7ee28f3aae5b07ebd4ea5c52f7719dbfdb47e565bd8453
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:ae0b9232b3ec92fef41a9eb4849c0848f7f8ca7c05aa33fae6dba07badbed038
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:c9aac112d56b8f5bde9bb03090495c4cc80d9e56eb494271b07639e6435b53a8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:6542c14d1fdeb64a8c2e6abd39529d0d3eafb44a0daee1cb4149736cb46e4e2e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:3e0e0accb562a58d6a6380228ef1471ed319840924471984ca6c8bd8860883ba