Sign inSign up
Zot

dhi.io/zot

Zot 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.21-debian-dev, 2.1.21-debian13-dev, 2.1.21-dev

Index digest:

sha256:296c5dbc475334807cd182e24a42626369aade27f4c092755c37f9be35667689

Manifest digest:

sha256:e3b7b8e620680c9c43eef07de831723902e43f3d727192ada565f48c972b65dd

Size

72.25 MB

Last pushed

5 hours ago

Vulnerabilities

1
1
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:f3eb9414538df322935e34a788f4a506aae696dc8fa78adef0609dae26a3624f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:9ecc755f0f1ce5d53f5abb893710cbffe9534dd988c253a936ca945830889509
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:763118e7a9c915ba57f2c435bb2fed0bba9df549e754aa19b81f467ceabcf05d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:d68ecca798b6bdceb18c93aa436710b444c7e364940ef78536fb6956a40796d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:d6e4dbdac955938e96827c29a534680417c0f9a912b12d2744414d2ad70f8a05
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:c8d8476b91188062326cb2a581796a78300ad9c58854321f5bb6acc957c9e202
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:9ce43be5c4a6d776a705aaaca9160d87e5a590d060be1b22016f441484aac1ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:fee459828793c95fb3ea10dd2d474032d2e27fc9b63fa0f3be56f1ab0536af58
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:b268badee2d2c5985a6e6d9b9cc77b8a3676a1c9feb2e203122065adcc0c4f77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:f664c80fd250a22313d0dfc1329fdbf5bfc470a1c7781a74f806dccb3758122c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:302e6f4a8b52ee909365484418079676a93b345c811ae452e2ed8fe2a2fe6048
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:8017176361cd52b992ad56c5fb6973151e8b59b30a0c22a6d6e29688be36b55c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:4703e5ac0691a828c90305ea5a306ef9d45f89101f81f56265924535f08feef1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:e726019c8e076e279f8de8512b3ea8a67bdc07869ac0c2f5f2b1c7d7c908af38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:9b89ad1670dfb164cb90327addde61885e8dc62c0e448d00e4601699f46717d1