Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.6.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev

Index digest:

sha256:0ea73b80d07ac6c623b5d86f36e686f554106b548bb43a829c45c1ff8e1a2424

Manifest digest:

sha256:566d8a95429f5313b961a3ec9aab9c82f14971a1dc4cbbdf324ecfd8e292635b

Size

56.44 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.6-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:280ec2bb942828856edf4dc06ac067ee009cb2f6c2bb623bce0ad7ced4519251
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:2fe7d10feb1dd190a234c63049d3d908d2158db06efa26300ee30df60c1acfec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:34aaeb3a9c7663495f8f3d3178bc524bea2f37b75100fbcebe4004d9b949eb7f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:e16d3c8d3c2557e2a2ce8596b41e471f31b154547db3d7e9a85b6e4dfd68ac8e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:abf8f6e1e1f742b0b110675f0445013efd0108b9ec0330b5137524846a817713
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:1dc59fd836c741ac5e362a65e9adf2b720193c317f8a3f9ec2bd893922191efe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:9cc521b23d917d3da2899bac95770c8b0967efedc95d4ce608e5fbf29bd30ac7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:68be748ffa2e93b5a6ecc044469d09edaaccb1341e84b3a16439ba23234c4dba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:145366966a507033e1409f2f33cb24de598563ab527854d575d1bc13f259da88
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:2e2c5767768698a2caa936517c372a60918ab8a1b123b0e40cd86dad588aae66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:2815538504fadb496c5d67000374421fbbe188df9e88f857d65cc171916b52f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:727a60b33012a8802c9a558633286aa337f0675b50a92089dcf2f8a964311ac8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:1b482c8133d1175ca3d2a188e8fedd35023d20b28cc0b5478b2ca703eb1e43bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:a64ddfaa8a58b67794592163c2a2127517f9afa344fc9a3ae8080fbc1c37fc6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:68026bd8f63b1fa9ac05a03b4a3dde2f1d76be899dbc4207513b9cdea4e5d0fd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:39d4f4bb6bdbe0619fb9f625549c890adb5e32dae8b86368f63662b5e6e8b76e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:c6d6a4ee831bbef0c7d6ae3c16992037b4768f4d2ed3e7e839a262aa606155ef