Sign inSign up
wait-for-it

dhi.io/wait-for-it

wait-for-it (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.20200822-debian-fips-dev, 0.20200822-debian13-fips-dev, 0.20200822-fips-dev

Index digest:

sha256:a798e34bfd47d72885956f917d0b011c144cf681a04a723eb1b8d79f2c5fc3e9

Manifest digest:

sha256:d48417be50ba5f3b7bd25fee6a3209177e702d265bcad09a58eba2af29b78a4f

Size

24.56 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
14
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/wait-for-it:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/wait-for-it:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/wait-for-it@sha256:65e7d6beb0f924589889a06d620bb0717ccd11fb58ef859885601e6a9bc9d3d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/wait-for-it@sha256:e1e73dee94789a8bfc066782557d92e16650dd9e672e77e6f873f7a0b800ae73
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/wait-for-it@sha256:7ab65c77972ee9e83924eee997f5687860c30452a63d1834023f0c3f2c540861
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/wait-for-it@sha256:f8fa86315afd5d6a0bb531a8f3b6cff0263679e2f5e13f0796bbdaf54926795c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/wait-for-it@sha256:f6edc11aba20a084e80025278f3ebea978ac386607d8123a28d382afb3bcc732
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/wait-for-it@sha256:56096603d8e0ade3cd3fd011f6a0b523d86fbb1f9f7293ac3b81111f2a8fb8d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/wait-for-it@sha256:d983503129991081e37324fc93c4f132bed2908d138f31a5ecffc6042e42e749
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/wait-for-it@sha256:88552f5ed3af63469c0178f6524aa1effe450bd61479456923114b56cc12b321
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/wait-for-it@sha256:4a785173f4064fc11a868e5ac2dca009c2696971ee8199b233db40a5fa11ece4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/wait-for-it@sha256:7551fdfca4de3fe1e6c3ed5af765fa106934db15a73df057e844203a4da55908
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/wait-for-it@sha256:286b4732ab3c4c412f3ca7d53f10d5d3786b60602647bff94582be4953530baf
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/wait-for-it@sha256:37410eb5585c3b4b7f10052ff9e2edc9d8625dd94cb52c74fbb652c19bdf1f94
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/wait-for-it@sha256:a3e72211520b13e21aa88df8409c3c875cbe25f9394ce464e0924e72358dd097
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/wait-for-it@sha256:2399ba041ebc8f834315f518813c7cdb146a59f577fee6fdcfa8ae0cd9a692c6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/wait-for-it@sha256:979134754f6ac15f4474d6edc888b78d02c415bfff08fff8dca1ff31ab6a4755
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/wait-for-it@sha256:c45e516f8b8a58ce66eb1d051dd41b32a54e327a67d637df10d355dbc9e945c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/wait-for-it@sha256:4bec20210356d7688b85c3a5138febc3ae84902577f05df8c2f29a78362b503f