Sign inSign up
trust-manager

dhi.io/trust-manager

Trust Manager 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.25-debian-dev, 0.25-debian13-dev, 0.25-dev, 0.25.0-debian-dev, 0.25.0-debian13-dev, 0.25.0-dev

Index digest:

sha256:99e4c4e7b6686fad96fedf5b0141fd15792780b2219c24556a838f78ba03f018

Manifest digest:

sha256:7fa3c6972fafdb160aab31635915225f508c5bcff722fb1296194e12e81cecb9

Size

42.94 MB

Last pushed

15 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trust-manager:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trust-manager:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trust-manager@sha256:763890d5cc8daa972a6f92b162d94ff469d2c990dbda43d0799e3ec16b0fdfbb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trust-manager@sha256:74ae3f61a506601665763ad66a15e8db5990bb1c1180a2990b674ec79981a6b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trust-manager@sha256:2bfcce67c5f8144e296dc34c7d08336970a8d46300c1e4794ca4887b93c187e1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trust-manager@sha256:e7f909af40b2f3e7e94a3e9f615cde5cc77fc2bd3d3e0bec753ebc31661b72d7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trust-manager@sha256:907aecdd6c648f61d04ad6e2e362c14829c1d666c638535b9e1dd6851a662a2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trust-manager@sha256:49f1a5b23393c1ac77fe0492619b60a5aaf9059dd47a0ad1021594833aa5b285
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trust-manager@sha256:feb2935d20c27fce5e34f705b8daaf44e507fb30de27f792684a5008baf86aad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trust-manager@sha256:fb9cf1f414039b94c92183d37fa475a99922aa9556c8ca5fdb92141312572728
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trust-manager@sha256:3f4c72ede2565f643f93f0d278182a7660de40b7a00cba4d803749b3db8fa681
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trust-manager@sha256:6dabb994277429dfdfb28e1ce0a68b3b15098d2cbcae7529a972ff2b54f3fb52
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trust-manager@sha256:527762c0636965fe3a27816946ba6dcfdb27696c63239968a3d764bd10619f78
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trust-manager@sha256:c12876ea8539920273f8d24480b5f1fb2811b21777c21037cfdc8c80ecb34c5d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trust-manager@sha256:fb9716a3441f09de4d147d0cc4363f544ee9b8e2f116e5c411492ad4b959497a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trust-manager@sha256:27e1122ef62d9aa9dd6c1a764bccc53f126fa981bcd9c7a028307f92cd99e755
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trust-manager@sha256:ce8c7a8a75af6e4053bbaca4666db37c6a0537d2ebd0ed2266e3a2f07a42c86c