Sign inSign up
Tekton CLI

dhi.io/tkn

Tekton CLI 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.46-debian-dev, 0.46-debian13-dev, 0.46-dev, 0.46.1-debian-dev, 0.46.1-debian13-dev, 0.46.1-dev

Index digest:

sha256:e88cf306ed4c28040ff0df73a7593d8c0f1b76d2c0caa40eae364d62fbd6a436

Manifest digest:

sha256:217fdf99a28818fd46fc3edb52bea5d69fab11e86ce63df9c3f89230f399cc18

Size

58.87 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tkn:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tkn:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tkn@sha256:981906a1ca9435c19480e17e3688d22644f1e1ac2f172c1e93e7b89ae8ae2488
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tkn@sha256:ce9119d0358b3db83b795ca74585f336ed1bb927722e605cbf9f8d7c620ce8be
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tkn@sha256:17b0e03b564729b8af3c8ad783cbf9e5cb6b8e04b1888556ca46e1466883d0cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tkn@sha256:ae4c7626e1ec63c8c1c7eaf4a9044b45e387e32adf83e05357521255d7288aee
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tkn@sha256:5fe900e31ffc5570fc8c0d7a511d228dfe98ba69c0c1d086f554bd43ac78651d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tkn@sha256:bb44d7d9c108ae0e3ceab2ee165e96152b2f31ebfb7028b4ed9fa1ca4de27095
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tkn@sha256:2fe7321761875e6fc281aca54ba09a16777baa44029951af07e2c2ea2949e32c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tkn@sha256:389a62e5f617d2649a01845505cf0accf5b4280746893753d9466059ce36a0ec
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tkn@sha256:17d1d1f00cc12ecd25bbe93390ef8a6377932dfe0b7b0bb6c314ebe919559012
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tkn@sha256:90fdfeca9e9fdd40628b4bf04e43519bd836af836c815f8d65d16d06c2d510cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tkn@sha256:401c1267cc41e544f6095e0b495f764c3d246fe23ac07e5981e929cce627d6f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tkn@sha256:cd595d2b23cdaac2faaaa5d24bfb113baba22abb7ac101a9e5d10ac4a3e6d2ff
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tkn@sha256:9fd491dd1e2fb95209634edd6a1e9fb3ba79d14432d21ef672d77828518bb16b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tkn@sha256:d49033b0d76d99aa1d600645c93230414714cfdb3f58693e80c0491378984c02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tkn@sha256:18cf93a57c26228b857c5f0b2304d3458225cd3f7ddd4106b6f3b92ec523cc8f