dhi.io/virt-operator
1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.4-debian-fips, 1.8.4-debian13-fips, 1.8.4-fips
sha256:4975720d298f5c59e19fc86361a54909d52dac0e608c5be07c32e7ea570b4f66
Manifest digest:sha256:2dfe4b4af97b4ee48a0c0b7b3e832f667012fb85f3f284347c21fb0ded65b25e
Size
25.55 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1.8-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:9b11f8378fed9704a810ffa5aba3a8a386b0173ced9ef48d9b7f740090f86a46 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:7b9a8970f7cac8167e499505d83f7911b4a97e86b5021149927ffad6d234c88c |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:c0039b3cc38d1aaab7a3229c0ae324ce7bf62ec05bb5d99d2a52d148d405d3ac |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:b746199b352183647486d81626b2ebfbc326745a714f72c9d25a74d657100fb2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:c42a3bede145a4ad14354c52b2783ce0bad4791cf5bb192867309048a2ecb0ac |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:67bee4c38432342de2b924a4d7c7ab533dcafb84c1fe97094e2a73893869adfa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:e32cc87ea86974078f490e94a4a1e37a36e43a76bb524adcb148af9d3a5bbe15 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:dd000934bae4b68c4f88ee436ecfb1027b1cfdd9828bb455adbf3433117350ea |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:0caa70bd75f736e7ae49111880e8fa930e88ec50f1a9b71178c044372acb292a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:1d33cfc660be16a8ec60b003cf91ce48c4bd268f88eadd667d940b2fe4a449c2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:7a6d2840b298a6cae40e2174076ce8d280fa62a5e90de28f330ed359febbc902 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:4c84ddc5ed0a7fc8296defaced659c73f58ad5028fce91799b2551cc0a3e27a1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:a244fa5825c6282ec96cc6d95a01004d191629f2fb0885f6a48cacde972c9b76 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:c977a874a638abc30c9bd83364cf09c19a6021c45cd260f4a6b95bf254a50a4d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:79a3f2c21ed9d1210fbac56b9a7ed88a302faf8ac4e99465155ba4ebeb3e4525 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:28183a7656d7a9f04cf53aefda8854b8b16dcb370bbe6728e81ab855e26d4f14 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:6c07de906f2be5ea6a5553116d1332141f3a318eb9e54e87365909d0850c6e2f |