Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.24-debian-dev, 0.12.24-debian13-dev, 0.12.24-dev

Index digest:

sha256:b1350911d0de73a88afb48768418faee2fd51c1086ff118873936f561672c175

Manifest digest:

sha256:b6fc630ea41e9c1c6e19e46973ad66e9b624c0f251d9800824e482635edb4d31

Size

58.72 MB

Last pushed

2 hours ago

Vulnerabilities

1
5
1
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:e26fcfe0ef0a086ef70e4adf2c0ab83651a64c110ccdb6245944d13ba2f41d15
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:ae4badc5fd68dbb733c7e53945fcf3cfeb598ab44099ca553f13bdea6a537f06
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:fa585d830c0d0c9a3321f9a3b82f05c26405b5b1e64bd77799f7b8c374a21929
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:a02fb01d9dc9e6f0d1ae3f32ea506ec1b0e07ecb4146e787c73a750c65d2f9b0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:c34795acdb520f4a24bdd94946ba4b28b232d7cacd6e1b4fbb80a3ff4e3d8822
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:04b5c75b3450d872ec8dc2e8c7b2a0ef9bd5c613a73016d7bbb85898b1e281e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:adc5c562316b1232f915b6b43b9178cfaf700a951b3edb4ab832d382d2b4c9c0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:30685c63d0ad8740024961d5507ca7aa96cead0b6854cdac291dd88f29c9a8fe
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:7116a701585272a6615f6f1078df4d37d3f08509664b51109f7ffd1099880ecf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:b65f833c985091fb952ee0505dd1a2110e5ac1287845bf9db9d447d4f5bfa7a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:c299792f8ae2598e3ba4fe38e343afd3493536f981e7d28965a6303d05c65a89
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:1a4f430d7721ea5caebf9aa3a23fdb0b6c3f4f6187a1a9205eb9e844234cc6e8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:4fdacb4ed22bf3a16b9669b8ac05c025ef872359e41029ba960ea5c271e43dbd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:aded03094890cde2a58828a02ee9bd59ad871c7fec9ddf442564d9a8ebfc214e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:cf296dc93a2ed68a1ff9293fe4fbebb5b2190059f9a44e8af64f20e9ebd00add