Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.21-debian-dev, 0.12.21-debian13-dev, 0.12.21-dev

Index digest:

sha256:c1b4056237c0212a21e6a8d8b5576d07d196e8d05cccfe4d8d4fb98216b54e55

Manifest digest:

sha256:7dad6bb26faaa4b3b64eb3a93df2c0c568029ecc458131c1b0ebc39dd084df92

Size

60.82 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:899ac1b6c99854badae442d4ea60800d50097d401e3ed29d8fea7f514c1bdb9f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:69eb6eeb721b929e097bcb6f9c5ec875fc15825e051bacd22724171bb3ac8791
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:59b00351f79365449f2b105ec347a9f41c1e666fbd5748b68ba7fbe073a40031
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:0c5f91d32f54fd6218b1e4115075970d3714b5dcdaf34b38448767e853903c43
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:17f736edc0954cab1c80338f5784e174762dddc98c26998b343dca72c023f8c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:163f8d5710f0c198a48de71d21adbaafd4e01c0787d141b5a7e33b57415eb406
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:a90b7c3fc5b8dc8d8bf542b5dae25659e2e41ceccb89000e4ece7a28266a22cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:5a223ae1dbd924e1a53313384adcb10a515add0e68a894a9b93db759e8c573f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:1af51a8cb35e007e11d69f007bedbabab96748820654441071a4a1a5a4d9bc4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:8b3caa98b27ec08089bd8ace38799fd94c4b7b72c55547c257befddca6a380b5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:3931bf3d8824b1e9706357d5cfcd2a9d7fa20dab50ee1fdf02c1dc5cd23c1ae5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:8c5cd423aa9bf5bbd5dcf9a069b511e8ed00dadf9003060d9f9e0790e1e13e2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:6be2ab197adafe3190866778b2f129566ac098644e1b9260ef413bf8ade0dd8b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:8f0965968bdbe15cc296d0e6b1bf532b0ae7dd347ff3720395f633302e329ccd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:f197a0a6f959c41edbb3f4b00b58fd1e125426586175847a90a96e9b6317bdbb