dhi.io/virt-api
1.6-debian-fips, 1.6-debian13-fips, 1.6-fips, 1.6.6-debian-fips, 1.6.6-debian13-fips, 1.6.6-fips
sha256:4e426e7dc4c140baebdfe5f810555ba2f581861cc025ee0656e4d6bb73b0dfe5
Manifest digest:sha256:8fba33be1a5653c252c94521f588b2d7c66cb2cb2d890e350972aef971fa10fa
Size
24.89 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-api:1.6-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-api:1.6-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-api@sha256:09e0e393e2e47502b2e55c725c814a91df68d6c9c1b5397a2a673b1b1e1fd583 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-api@sha256:140df47291862729ea021ca15a91821491460464d78815588dd64008da9a9edc |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-api@sha256:f49e2b24c10916ebee8c79a8437a53cf310b37d6d0ff18abb6b58676d35b20dc |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-api@sha256:12659b450c557e915373374ed45b7de94341fe6c9d0e1a9cba40e0cd51b06e56 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-api@sha256:323e959b8a415e246e50ac47069134713e0f66d06e7fc767fbbe66c0210e1051 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-api@sha256:22cf13ea6cb79a53a391cb46c6c6dc1f2a93f31fe4fc99ad6d9eecadea809186 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-api@sha256:e715f56820901b580d8a2c71ec59c7d89bac76cc3b45c54e3753bd1b2efd7dd3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-api@sha256:1142fcf506e59f3dd33285468ef5b4b58d55a80ed0e7d8836b534413b49f70b2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-api@sha256:3010b84b4f43a07ef51cfa1e9d6b26e7c40454683ec33d6423c8a7c843bf6578 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-api@sha256:becff81aad73c38ca7fe41ff67502e9446ccc55cd32e0441dfc597e0a4903a75 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-api@sha256:bd87fbd962188f66c27dbf2452562e5e4ca2f32a776757f4ff35657e4e469601 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-api@sha256:d2747f8dba15698e81accfe629b1b7380a13b93d63506edc207049f6163a2e76 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-api@sha256:be172656fa677be8046fece67a569df11c16b35af150baa5dd1cad155eb2723f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-api@sha256:732627cf9da8bcf799a88b4a1b0a5c8114326e97dc05c43985b907296e04650b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-api@sha256:eed70726f17c1fb6b9ccdf12c9922fa176b421ac16cdfada0911e860b031f41c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-api@sha256:38f0b4e0789bd4f8c65ac1ce627cb1cdf4e1afea96f6e392a399a8bb00aeb308 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-api@sha256:b1cf32d86ef00a457ed968cef1471942f5303b91bfe5223bff55b86ec316ce5c |