dhi.io/virt-operator
1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.4-debian-fips-dev, 1.8.4-debian13-fips-dev, 1.8.4-fips-dev
sha256:6decca05f061b42eb2201f4dad4602ecbe73f1b3a0278caddb74805a456799df
Manifest digest:sha256:6fbffad2f9556676fbb1cf9698ebd9dafa27153a497c6072fcf02fb98c4f0d05
Size
57.58 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1.8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:c1c2471d5851025d167d7cb19a79e7b2f29bbdae5792c17b5df6fcd8b1b3a833 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:5fd23fa32102b4fc188d76f8a7b4b04feee60e3da124070e306259103c3eb2a9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:5311e41363fa6b13bbdc3f4cb808794f29116cdc00cda073f60c70af6a4c9096 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:2e7463a4420896d6fc71c47f2f0b5722881ff04d6e5d090b7de14aca2a7d4c84 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:12764deb7d31bc39b62bb8cb725e9a9c58954929b66569369da94dca602e0291 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:6a98ce9dfa4d4cfa5762a01da54b1f499660b8b1eb32c1598f1222ccc2050a3c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:7825ac5a58d6e6a696737cd9fb5ae87c2e88b90b7e1c373cda8a447c690c418c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:c602bdf0c71c5b1644fdb2f30124de54ea9ed11ee93f6ed29138b016199c89d7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:45c545968caf9b01b2190f1392a0afd8f98bcc1e767cb85a98fc5dda3f3e75bb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:0aa7eb443feff95d994da27feeea409e21058be222379ef9997af075dc123648 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:18aedde0fd69fb5aee6a0bce2557e181c646a009140ef570dad6e25c24ecb026 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:3d98b9b534b27b38cd67238039031dc5d424b7db0968b251cf24a4310b2ab4ff |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:86b0ebe677fbe28143984650b725e25c3004e19fc500b1dbac597b46097dd31c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:6029ce80986dca09abfc06b16a2fecf0f8a538e7a1029563f88d5411c15889c9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:d6a6acb08be5b2601260b0c0e1f59fb4e06d3384fdda87e45dfeec0431686c2f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:ac0584a01d975a5f8d3eb787cd5f81c78bcf074ad4cc0896df97b062a839ca9f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:d96b3de86178866c2fe531efd6bea9c85c3831acbb2397f7b8fed722a704e683 |