Sign inSign up
Tekton CLI

dhi.io/tkn

Tekton CLI 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.46-alpine-dev, 0.46-alpine3.24-dev, 0.46.1-alpine-dev, 0.46.1-alpine3.24-dev

Index digest:

sha256:347fbf354b5d1e68ac991bd7159416eea4be80a6b2af497b30c8b949e37769b9

Manifest digest:

sha256:535c8d871db9512a7ed9d1cb3a0a8a589daf96ae2f278673e144f5f3c7b21182

Size

39.45 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tkn:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tkn:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tkn@sha256:16defb50b8d9a3bd512fc2868d040fc4e31d30b2163e1072a5fd828127f00af9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tkn@sha256:7c24e66d781eca02dc70a8c883e00a0e116b1635633d9433c33e04e817cd93f7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tkn@sha256:1eee4878bceaaafa26a446448e9a7d744df6fcfe42b2340afde8588cab2b9504
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tkn@sha256:eb9d3101f39bcdcc6d06dba334a25e9875fcaa9f00f170e33d4a52897545b2d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tkn@sha256:49922124dccee07a3de18a5389366856b8d61b5034e79e19ff6af69b2a571a48
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tkn@sha256:48c98457f855a0a19107e04cfead8b1eb9423913f29e1ce23d27f827dbadd708
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tkn@sha256:fd478c38197b74f821eeaea41a7b6dcfb0bf6bfe6ca4e0be461190d8078db8d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tkn@sha256:e07f0aa1eb31f0951f02c11091850d4135f5a0bb60992f0718b2eccc68b81e88
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tkn@sha256:776fe6502052476f569b7393147324becf718d8d76f3dc5cd0b858f1c7f53de8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tkn@sha256:5f0d2acc3d714e569a750b621c06d8d3029acee2622f614ba679b0adc3d31b7e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tkn@sha256:3cf0f0842bd2a7faffdab91471bc6e1ba2b404cc3452d67c0ef38a283e77bbc8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tkn@sha256:1f491f4bbdd8f4a6f6ae6a878c4604f67662e771a3614b268270c9e43c26193e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tkn@sha256:4b2607991b3b58642a9bf79ada641d63320218e56098da49ec0d613305b33355
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tkn@sha256:b6bef4a3a93399b9d76ee6dfe6c83a2a588a6f75eaf057c5de7ba045ac97e368
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tkn@sha256:5f9f05bf29eab06365a8708df06fd019b0402d27faf7ff879ea464ad950d4c84