Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.15-debian-dev, 1.15-debian13-dev, 1.15-dev, 1.15.9-debian-dev, 1.15.9-debian13-dev, 1.15.9-dev

Index digest:

sha256:263030e0529916d705ae6f73536d03e3d73adb6934d06b3edea0c6747ce6107b

Manifest digest:

sha256:72f1665be73d697fcea0c85411369dcf880a7d73d05deecea925c1fe7f22a5be

Size

104.42 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.15-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.15-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:53f91d3730dde6f514da122512b31493723c369db29059b7ca18fe88d72166e5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:7c119883f56689acb2386c4a224ec9c3b997d91579d12494bc4abc2aa51a0fc6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:cb829188da4b76b8ee6b68eee7950fbce2ea50822e2f42194b25f6d6f6f2ccb1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:26e52a20e5883cfb6161dfb630ec310104fb9401020260ccf7616647dc41eb34
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:99876590ceac3a83e2aee0b01defc06ca0274c5cdfa666e82684cea3e8cbc2e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:e0b890effe80801a7a81615874b83714aa3b35baf113a6009a5e9a91ed87076a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:e2dba43085f82117d4b1d17822ac49c394da448e29695a0f5972a42e8e960a9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:837ff94bb9c5765954541ef05a33d9b66e04575a2585f74248a9033d9c2969d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:4e6da63f0bbc302681b7c391d7f9ccc16885f36ad7130d71ed25aef0f2733821
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:f69fd4fbc8cd6bd80078fc5b3f4df11f1d190c201ee94d98cd7ba0b7565911c3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:c560583374b60943f3e32ef36a6075105f1e2609b937e6e9437f5d3a81b85ee9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:f659bdb9773c63f851bb16a5c67c40bd6f566e37e4289a19071b1fd97d09bc53
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:9fb278b37ef2f7d709dde3d3472e74ba07afddfa6ad04b6c37b19ef8a80ed3a7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:8bd857c158cb5448a13f0eb50111c70ca637721c3681c94ab513072f3fb9b3cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:1bb70d3f454102dc981ebc8e24724e1800123164bd5077b8a1b3453690887127