Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.4-debian-fips-dev, 1.8.4-debian13-fips-dev, 1.8.4-fips-dev

Index digest:

sha256:83a38d76424a729a4f7baa50ffbc34e4f07f9aa9b3dea4ffc5eca547f3ad3b12

Manifest digest:

sha256:43d0e4523a8a2cd24f8cef33b7e6907469d5f5a6c74b47f8f0fc587247baeb4c

Size

57.86 MB

Last pushed

11 hours ago

Vulnerabilities

0
2
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:52770ab261743940921b9307cbf475706852de3e529b4a74da4316da0edeffea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:b66f21f2d783b630ad65de2069ac5bad726555f6b563f737026e474eb0e3c52c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:6ac4febc6e531e395a36af78976201ddddf3a90b3ea59b07789a013d53f94813
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:b5f87e0fe316bee709806e4b6bd6e1de2bf6aa607e2f9ec3e9c462c4e5356af7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:8e9cd2e53b6be8f4a30e1321ed09170c7876a8919f8e3b2ff0ef06541a82d4fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:c835c66547f0edce58c6a7d38aae3de70e7c78e0198b2648c2d90f84ececc692
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:5b230bf768978ef33a3ab5274300e31fadfae42946ab12fc2d2b061e42f72890
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:50ecd38f7f8124d33eb8d586bda8c65352be455262415150c7aff8aec5fed5d9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:a0a5306c27a559dc75b06415fe63544faf429dfb8ded8325fe3422f60eb561eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:dc45b35bb30454db7a7e57e96d3c8504578759827bb249d0803c9f9a29e47796
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:4e4cf8e159d490b8097cd578cf13317e75d0221900f350512b62a587e6dc6d49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:5c0280b57544f29731499434d808ea3c27304fcc2dc16b88196d57fd7ac921a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:1a37bfdceeb78343199628d3541ed13cddd88279455b9ec67e266025b1c87b4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:b677d115a14f3db7cac89c836c523ac0dc34f48e189e9c7ef1f2cf28835131dd
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:60b243ca2bb50c8acf35221c18e5bbc98a42d0ad4fa858e4d2ebc7f07f1d26aa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:4941d22df33bb8a64a114573a9080aae1406d46f28fb37823524bcd5db3bb589
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:6a52426050d459058a8e047731837e50214037418d4d5e6b7ace7ed678e7ba72