Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.4-debian-fips-dev, 1.8.4-debian13-fips-dev, 1.8.4-fips-dev

Index digest:

sha256:6decca05f061b42eb2201f4dad4602ecbe73f1b3a0278caddb74805a456799df

Manifest digest:

sha256:6fbffad2f9556676fbb1cf9698ebd9dafa27153a497c6072fcf02fb98c4f0d05

Size

57.58 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1.8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:c1c2471d5851025d167d7cb19a79e7b2f29bbdae5792c17b5df6fcd8b1b3a833
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:5fd23fa32102b4fc188d76f8a7b4b04feee60e3da124070e306259103c3eb2a9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-operator@sha256:5311e41363fa6b13bbdc3f4cb808794f29116cdc00cda073f60c70af6a4c9096
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:2e7463a4420896d6fc71c47f2f0b5722881ff04d6e5d090b7de14aca2a7d4c84
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-operator@sha256:12764deb7d31bc39b62bb8cb725e9a9c58954929b66569369da94dca602e0291
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:6a98ce9dfa4d4cfa5762a01da54b1f499660b8b1eb32c1598f1222ccc2050a3c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:7825ac5a58d6e6a696737cd9fb5ae87c2e88b90b7e1c373cda8a447c690c418c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:c602bdf0c71c5b1644fdb2f30124de54ea9ed11ee93f6ed29138b016199c89d7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:45c545968caf9b01b2190f1392a0afd8f98bcc1e767cb85a98fc5dda3f3e75bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:0aa7eb443feff95d994da27feeea409e21058be222379ef9997af075dc123648
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:18aedde0fd69fb5aee6a0bce2557e181c646a009140ef570dad6e25c24ecb026
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:3d98b9b534b27b38cd67238039031dc5d424b7db0968b251cf24a4310b2ab4ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:86b0ebe677fbe28143984650b725e25c3004e19fc500b1dbac597b46097dd31c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:6029ce80986dca09abfc06b16a2fecf0f8a538e7a1029563f88d5411c15889c9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:d6a6acb08be5b2601260b0c0e1f59fb4e06d3384fdda87e45dfeec0431686c2f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:ac0584a01d975a5f8d3eb787cd5f81c78bcf074ad4cc0896df97b062a839ca9f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:d96b3de86178866c2fe531efd6bea9c85c3831acbb2397f7b8fed722a704e683