Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.9, 1.14.9-debian, 1.14.9-debian13

Index digest:

sha256:9761b5f10aa2e9731fa9069bf2b37c249729b704bdf5d5016a938058cf140e59

Manifest digest:

sha256:cbf13cf9897bb4373abff8c4c3161d2c7eac3e0b6a5d3deb86d6b3a80ec2bd00

Size

60.02 MB

Last pushed

12 hours ago

Vulnerabilities

2
4
0
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:817a2df8ca69265480157b2d10e4bce9d026258e0ba4b674889507f0d6471971
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:610adcb24f83fe08c808645027eef3ca345cb2da66c8a3b836a99fd51e18cf5a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:fea8ee3730c03dc654d46243e4c4aba8f1c1008dfb03e95b245aa49b2228d944
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:c3b183d4514f0dabec0fa622e83923257138095ddfe0136b76a39f18ba4d2dc8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:0119e3d109cf6cc4cbd84c3929fcadfcf698cd8ecd08e83e6b920fa0f21c48d2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:e3910796a51734dcfaa6a863c13b7aafa45a89a71c8c71ebfbff8c60ce50505e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:6fa90f322ad306b994a1b37003d190b337312020ff30d91d55a7459388f7402b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:fc59845f5b359ea6d69dfb1a29a6806ba29e843ce02aeb81535f9b0bbc66d064
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:57527369745e2edec2a21bf60f5451287e8b5601c2d8b6771d518cc9ae996d50
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:20c4a86237ecc8d1ea2cc0a234a4f4084056ff130d1ac19327555dabcc55c3d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:dd27bc34e344e5afc874dde1d2ed558efda84ec25cfa42e2ac0758989f4e6f07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:aeea45207db15913dd43bdae537e7f632d7ce6ce997fd6315c2e7f4d38b3ec2b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:34bf59be298f978e4ab389855c155171b86029fa27bd7b20cd3781917264ee0f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:75fe5180b34e1514717f558a33207b6dfe0fb8a9f1077dfdcf50086e564e0ce2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:6c29a63ccde1ca2ba0ff09fbc70ef8948f7c2d835f134a139f456f4915639483