Sign inSign up
Tekton CLI

dhi.io/tkn

Tekton CLI 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.46-alpine-dev, 0.46-alpine3.24-dev, 0.46.1-alpine-dev, 0.46.1-alpine3.24-dev

Index digest:

sha256:9099a38cdc172b6a029c80e57f4b3ce91b61cff74250bb15fb9c744a63773458

Manifest digest:

sha256:e33a8fd7ace90606bc7f9ed418ee1f939f0522d971be3b6913408fa3bf9035ed

Size

39.46 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tkn:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tkn:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tkn@sha256:85a1ee308542119e5e46cd7282e8dd2b534de17310a90b1c777e40a36e48163d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tkn@sha256:fb281c94c7b20db05a9e7a9c31ab71cc6f29a3f2f0c3b8e7cb615b6f59964830
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tkn@sha256:ce7d378b9548013f3209d2d15279892b3ad0776fe8a8d0f3dc9e69c1f0020887
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tkn@sha256:95916fd31aab6848ec838ce9fd01fc190a27c569c652edb0af3541e651a6cc8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tkn@sha256:35ab84cd26099ed940f8d36f89489126ecfb52d3540991df3dc0688ba5c34545
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tkn@sha256:2f24bd33ca9e09a41c7788129fe172c6bd2515f84813319d01b8def2cbfedd2a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tkn@sha256:d4f8294f717efcac12cc7d27bed0170a6af0c88cc03d5ed1cd79be6ead63543a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tkn@sha256:6b2639f33fcef6d749a0c9531caea1ea7d2b88c069b51d7dd614aeb1f26c995c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tkn@sha256:fb12846935aa71e5a81a940769e251a0b4a41f9251ae683ecd76403301ced080
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tkn@sha256:ff7598d7855d5438ce445ee2db94fbab675b45301a2338dc646209554ed2d01d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tkn@sha256:14b1d2575f376ff62059faf9fc0a768b3f834cedf0eda3c3d70ddba25ce1d911
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tkn@sha256:600046f9ff830da307f71c1818d7becfac6d3de79dca92c0b6bf65e925a4c051
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tkn@sha256:2f1c70d2cca768b61bea9124da40caec32ee0f4039dc1ba76371ded62452a085
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tkn@sha256:0ef7fedaa0c8868eb060f9a65954ce75366b0f32dc21f63f3dfd8be186d9dac2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tkn@sha256:43145a6e27100ba54e93d12b81b4889686d2dcd493e2fda2726f2ede78587754