dhi.io/uv
0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.23-debian-dev, 0.12.23-debian13-dev, 0.12.23-dev
sha256:3bfb1b9e5b7afbbcffd9f8f9467c6cb57e1fd5e902275fded369a1c5f8a927bd
Manifest digest:sha256:51e8866c934a1585fc312fadd7193fbd81a8f5a093f2cf2ebc9e7edca20a78a8
Size
60.88 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/uv:0-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/uv@sha256:5656c3532afd454e64c3d600dc62f8b8ff66ddad68d8ee451ba43ad2282f3bfb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/uv@sha256:130d8645ebda5ebc7f652dc421de2cac84c8ddb0f1c4e725806b055efdbdd7d5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/uv@sha256:1ff0f0ad652ac18d4db7ab7c543e28b83fca6d0c00f067f2167099327943f7f7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/uv@sha256:16cbf5b8459225476dc86f53117f67cbb0e99e7794bdb6808f2f8786dd69e199 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/uv@sha256:0d715754cdf3455605ca14301e70f17ce24aba66e2fa61d839fcaf2c3cf3846d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/uv@sha256:4dfb618ed15d3b7259f4766dd5b36716c53870010843a2a4a7f624088ca11b46 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/uv@sha256:3b27203149126a6ea8a607f7df2579cd92b449c6bedc43e4c95b8e9e28d5738a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/uv@sha256:b8f057e4115466655c4425e83a65818f1b2910a1e42c4321b3d7490c61285312 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/uv@sha256:f6524ccd9f692a9a39ffeb3d328b095f4e55f3af06912457b3e4abc6d6c0131d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/uv@sha256:fc2ab474f3a2a0bf64a3efd75b25b87ab60ec39e34edcc98ec43ac4a89ad476d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/uv@sha256:a14a5e91fe951a96dd08553433e0159e02e321c241f3189af35ebd54cd523cb4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/uv@sha256:41a8492bfe4c6f61d26392e7f1cc86fdc4da39d318517b583c8cda916ad362b4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/uv@sha256:fc29006fd794356b07ea0db50e0c1cf6018a308cef2e34866bf6553d6620f9b3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/uv@sha256:8ab037f93cd5d6397641e3f78c200ff1a3bca0130201f75affc26ebd8c53bf06 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/uv@sha256:818407673bd6fbca6cb05bb23040459b7ca5707529b2728fd1647e678212a21b |