Sign inSign up
Terraform

dhi.io/terraform

Terraform 1.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.15-debian-dev, 1.15-debian13-dev, 1.15-dev, 1.15.9-debian-dev, 1.15.9-debian13-dev, 1.15.9-dev

Index digest:

sha256:cd73b9ec5799d253cc94d3bb4c0c01559ca29c975c09808f6c72c21758b1a956

Manifest digest:

sha256:c8a21566f77dc94fffcd38a746ab4a7cb58f7a405c8cbceea8c49b780cff21aa

Size

104.29 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/terraform:1.15-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/terraform:1.15-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/terraform@sha256:d5e4b10172ce53d6b2e162df147ca7325dcd909e0ac3c70bb7170e4ab0f4a46c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/terraform@sha256:aeda3f11d74850f782e81d754263d757667b6e0bea3fb5c794a0fa6cee2c0627
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/terraform@sha256:6adfb587d8c507ca536778123c198629cef74f3cafe3b1de8fa5444d1a0712af
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/terraform@sha256:a01e6cd86632aa2e384e2bc654bf2f54eed95c863681ce5855c8bcc6f9d0f493
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/terraform@sha256:a162b000cb158c0e2aeac39c257de61e03360f95e0069ee7a151f14d19b2fb6d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/terraform@sha256:fd552fddc65f857da0835e54d26c8f77829e98cec862ca49b715c4f9c32feac6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/terraform@sha256:1825f85cfef8b5ab75f4253460c4c5fb86786cd68bf439e89373e1087b739c7b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/terraform@sha256:94387927be573d0593a02bbae3b1bcd3b1bb194dde20d09aff83e6c2097492cb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/terraform@sha256:2a8000963d2378e55adacdcc7218953658d4313cf5429e7ba706b36d630bd8c6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/terraform@sha256:50403ebbc7c8d78ce05610f0ab4a2405d87c8941482a1547c2c7eb1ecab5308a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/terraform@sha256:ec7802e9234f82197ef2e176e886ae8197ea3c90ea0d51dac23e534a6aadec3b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/terraform@sha256:fbb9ec6e7ff1046bb697cb102c85f19632a937c8962b08e6dd6417dfcfc70397
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/terraform@sha256:1be8b042f72d43a7f437fec7ffa46e67d4432f68aa7dd892f89653668ca67b05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/terraform@sha256:b160cd9ee51b0c4ff36f060eefe6b079decaffa6596d7dcfbbe93331c5e2a84e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/terraform@sha256:a4537a3b86aaf8f79ee088af12925869cff5fa88063b2edac64c64a297f40bcf