dhi.io/virt-api
1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.0-debian-fips, 1.9.0-debian13-fips, 1.9.0-fips
sha256:7a7019756f1cbf990533e7fc1efea5bdb3280c4c21d4ab6bfdafa9fbf2be7db4
Manifest digest:sha256:fd2a805043d37c957f6a5c3830ea09a3f7f83db1d302aca070af06bb2fb5658b
Size
27.27 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-api:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-api:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-api@sha256:bdc1d60ce300250a777f023e6dbfab3e98f1870542115593b22e0ba42d9f0606 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-api@sha256:28af3227a9c1421c9816d26d79a0d66abaf2cd5ae33175a2fc8c93b9b18dd5c0 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-api@sha256:51972565271058d739cf025e83806067e3f01ccec2b9275e5eab226443d90806 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-api@sha256:4d4d9da5698a413c71f2f5141d1a157e666bf9ef76f8e8d42605544c2a9c8241 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-api@sha256:2ee4534856faa31e741457bc919037060fbf55d0f8dca3cbe70c73a0cc6a1bb0 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-api@sha256:a27e3c3b11a50ac7c7e15417fdf21fc26e6117f068f9053f3d8ffb20dbebe8e7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-api@sha256:6055854f7db95f94375c9692ad6159717f4fc827217cf6bc5df155701939ffda |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-api@sha256:87af282b949d3367b50c2315a755c21b0a6b2f0f2ff33a4d5cc620a2465dece9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-api@sha256:1af7659e2ef3b3d8f235b532db20be23e974721c2bb8b9f1833e0320dd72e7ba |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-api@sha256:d585b5e9d4424c64b38d4d3a3b8bbe3f50fcd3bd27e012816a6e315e75aa9615 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-api@sha256:0d39597a7e2761fa042584881ea935cee9fd8cad0355fcf1537d8a46bf6c9cb5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-api@sha256:1327176739c5f958e5c5f5c88d7afeb843e94c4bce486517092b8c735057e091 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-api@sha256:309e253e6c7a8dde3197cd16cf158be6bd119e13c45a55841b97044fb1bc573d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-api@sha256:bf716041a940c10b8245cb9cdfb3bfd8724cd62bac9d8340e9085530244163bd |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-api@sha256:bd1a5ac13d26b96f1b209d8fc22e8e7f14d551ef66adf2746de5d1a3bda56f3e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-api@sha256:bd6251ffdffe0abc197b0193368d93444b892614ad8be34fdc9f1b9d5b627335 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-api@sha256:7097ce670d978cbf2b452208863304d0ba983c380fb4bbe92381fd27b57fddc2 |