Sign inSign up
VersityGW

dhi.io/versitygw

Versity S3 Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.0-debian-fips-dev, 1.8.0-debian13-fips-dev, 1.8.0-fips-dev

Index digest:

sha256:7946f524047e7d8e294d4515ea51292b89ac4db4e5c9dab8ee1935a5e1b3769a

Manifest digest:

sha256:3cbd25624ae3f1be45e253be0d26aa1247e0eb3a5e262cb71f40aba29eeb7d1e

Size

47.78 MB

Last pushed

18 hours ago

Vulnerabilities

1
3
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/versitygw:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/versitygw:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/versitygw@sha256:7a2cd70005609a09b1058008daefbf4ebbd10bfda6977b7c77a9289e81d3b696
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/versitygw@sha256:acc7e88392dbf31378daaa094fdf626b2dd97fba7b915d1e32727e36e16f4709
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/versitygw@sha256:4f1d25abcc432fb46037320bf37cfa4b3afcf1ee9e628241907b660b1edc4357
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/versitygw@sha256:3706f57344c4f953ca78507c2606172cd73fdef5554454d810f7ac1dfeb2bc81
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/versitygw@sha256:7c549ff443e9947d120a7a84cde3e9eb699dd90bf00bc42ec191e55a11ef290e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/versitygw@sha256:a5f6768cdb4d52a97c25a083361b592e2c8c10a1c379b9699b680d852a577c82
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/versitygw@sha256:0be6181c8a1a5dd449d088a746dbd828c652757b9861a3fcbd2156cebd7b49ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/versitygw@sha256:67f50545722c7572a1b74be60c6412f388e8664ba84256ab1056913cf8a64233
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/versitygw@sha256:0da03766688f5ad01592e2af71678885505ed1038dd30e8f4c463343664a2839
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/versitygw@sha256:23ca029ca6fbfd2d59811a5af01093d04f9de58517e5ec046c92e95cf7f2ad41
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/versitygw@sha256:104fb184ae26f8885aafb39794450e5428eab933b458d7b2397bd0579473ae14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/versitygw@sha256:10906805391aa7815b5b240b4f7bf28d70ed7feca414b496867c9568e25b526a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/versitygw@sha256:31ee5564a9189ebd5ffbb8c901e7e58eb7fed7694433dfd72e81e91a913502df
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/versitygw@sha256:a22cc4bb28c19ee2150293d3f6c9a17ad05eaecd861799f83658d978c9bcb2ba
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/versitygw@sha256:df2c2f378922cfcb2c6343d2d7aff635e70a1a7df13898d3d21abfe4e75d180c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/versitygw@sha256:d6fc998647d9db8e3c70377eb4e1b39f76ca5c9a254763da29c33855962740f8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/versitygw@sha256:f4d853c8b84750431d5ca609ff58dea6c100845937840df438aab7dfb3959b70