dhi.io/virt-operator
1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.0-debian-fips, 1.9.0-debian13-fips, 1.9.0-fips
sha256:56eb9a16b56fc19ef9556783d70d14cec80ab5c58ae9c3a1fb386fa01733a1e8
Manifest digest:sha256:b7f149e6d2d3ae0bb3475f4024f075a6854833dfa1ca748992ce0ed6bb213938
Size
25.63 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:4c659f16d39607e085406dac3755c200efb35a8c6dbe3041318525414c7d0540 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:5c9ec675604200dc957c1e391455a4f190c7b5fd8f236120fba6ebf4ff2f50b1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:ad22112ba5ac4dc58a958b0f24148490986e9f079b0819e13532f45d39fac74f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:ff5877cf74e3125b7653d417c62b334f4af44093f009822721f0ce676fcfcb7d |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:da01e89162d8617bc821131371badf72c6664ebdd8cc40e9bd88ea9a635d1e81 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:a42d5503774b59d5557fcf95f6afc4e55ddda58167fb096b8f7c00d65ab1a56c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:ab52171141222e92b664bad3a086109d2013f46fc9cea9e0a2baa61046cd26c2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:89061cc0916e413f5812d130564e4af7b2e069bbf480582d2126428e0333bcc8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:fb7f1d7709ab6eafb817e604bed09d4fead17ff4c96888b82a9ee874f97e93a9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:759ea1d226e5818da52bee750345440f9d674d9cd14023d155e44f7e11e49532 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:fcf012b968dd4779d1821db8c0f22ecb30bb16e92db418ba9c4b1a79328b1dc1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:386ec6d92c1a807ec1e055e18bf140bdd6abee37872ffaafcae5ee56dbbc6727 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:be13b9d2e9e6ab5f5db9d8b1a7287df045f5441b36ac418356ad70cbe5391f6c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:33f936175d3a7a760255ae41f7ed5b6a65db53eca83439536571582869ce8ae1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:f1df7a501b267156293ddd74148f369f0e24ca7912883d264325cadbac7093f1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:c20660a7dd3714619a4f77af00bed343409ba88e8e568da4fd8c00b1984d77f5 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:f6589855735b4a3c2d0a3ba6180c355ca0940820acfbc77c82eac341327280c6 |