Sign inSign up
Virt Operator

dhi.io/virt-operator

Virt Operator 1.9.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.0-debian-fips, 1.9.0-debian13-fips, 1.9.0-fips

Index digest:

sha256:56eb9a16b56fc19ef9556783d70d14cec80ab5c58ae9c3a1fb386fa01733a1e8

Manifest digest:

sha256:b7f149e6d2d3ae0bb3475f4024f075a6854833dfa1ca748992ce0ed6bb213938

Size

25.63 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-operator@sha256:4c659f16d39607e085406dac3755c200efb35a8c6dbe3041318525414c7d0540
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-operator@sha256:5c9ec675604200dc957c1e391455a4f190c7b5fd8f236120fba6ebf4ff2f50b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-operator@sha256:ad22112ba5ac4dc58a958b0f24148490986e9f079b0819e13532f45d39fac74f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-operator@sha256:ff5877cf74e3125b7653d417c62b334f4af44093f009822721f0ce676fcfcb7d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-operator@sha256:da01e89162d8617bc821131371badf72c6664ebdd8cc40e9bd88ea9a635d1e81
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-operator@sha256:a42d5503774b59d5557fcf95f6afc4e55ddda58167fb096b8f7c00d65ab1a56c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-operator@sha256:ab52171141222e92b664bad3a086109d2013f46fc9cea9e0a2baa61046cd26c2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-operator@sha256:89061cc0916e413f5812d130564e4af7b2e069bbf480582d2126428e0333bcc8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-operator@sha256:fb7f1d7709ab6eafb817e604bed09d4fead17ff4c96888b82a9ee874f97e93a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-operator@sha256:759ea1d226e5818da52bee750345440f9d674d9cd14023d155e44f7e11e49532
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-operator@sha256:fcf012b968dd4779d1821db8c0f22ecb30bb16e92db418ba9c4b1a79328b1dc1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-operator@sha256:386ec6d92c1a807ec1e055e18bf140bdd6abee37872ffaafcae5ee56dbbc6727
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-operator@sha256:be13b9d2e9e6ab5f5db9d8b1a7287df045f5441b36ac418356ad70cbe5391f6c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-operator@sha256:33f936175d3a7a760255ae41f7ed5b6a65db53eca83439536571582869ce8ae1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-operator@sha256:f1df7a501b267156293ddd74148f369f0e24ca7912883d264325cadbac7093f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-operator@sha256:c20660a7dd3714619a4f77af00bed343409ba88e8e568da4fd8c00b1984d77f5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-operator@sha256:f6589855735b4a3c2d0a3ba6180c355ca0940820acfbc77c82eac341327280c6