Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.4-debian-fips-dev, 1.8.4-debian13-fips-dev, 1.8.4-fips-dev

Index digest:

sha256:d83a5aa5de7828e6f0a61bb221f8b30d1fae9396e9ce07d15a0b17ea42046525

Manifest digest:

sha256:8b470296c7e3dd4f8079fe8cff20096a1aff1fad0f0ebf35203c5c9ec0135724

Size

57.89 MB

Last pushed

1 day ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1.8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:6eb8a10c954e60f0a24646dacc3902c461eb3c2ed06acf4cd9227179de8baed3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:91161979933694eef0360b1dd7bbef36f154223b0d72f5418a44494a35f2fd62
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:fab5aca399195cb1fadb62c53d9ff8d7e95eb3566aaf68c05ee0dcc1038173fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:1f6c68b11cf70a5809dc731edbf97874b12fa71897e67b65d0e171888fd2c134
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:52e33859a948fd4e9e57f7db800d7169badf08e65d0228292847fd9561754421
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:23f96f839b0bcc09a3dbafcd06c1d2c6901bb1e910bdb091e1909f2e6f4592f3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:4c9122112007a0893833434e823657589925d89d49f7e12e621e9ecaf7d1a115
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:5e6a4ea8a04dccf634fe66837409e0f717be2ea65325f9118cfa0d8efc1e3308
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:74fe0c43bbc29a4291309c9dfb71921e4232b33bfc898831cb09883cda3c85ca
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:d9ac1aeeb0e33eb9b3538c32aa44e6d4ce490429a18c9c619026f7b9446e47b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:159311fac567d60c71ff3b80a35c9c4e774963fff8d76e12f1100269019dff31
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:57b418a05c3717a902cfee129de8c352ec86792bc08e685fcd57bac56372f344
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:d8650ff24e8e41981d9bd3d886c62442fe726ddfff6a441b7f7f561f6c9c501c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:fd975eb58f4d3f3d1532910a15192002e5513f54f25ebb5cf11270753a5ae3ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:176cf5a1c57cdfe2cb058d0e220be10993b908bd48dde4570e9a99dfb52df77b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:22483058c38d602124260db02e6fcb329e3891b386acda2c07ffb1b210e4048b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:cc91b231ac36d0aac4449404fd82f0cb6b51b1b35a4645289409db5816e5aa27