Sign inSign up
Zot

dhi.io/zot

Zot 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.1-debian-dev, 2.1-debian13-dev, 2.1-dev, 2.1.21-debian-dev, 2.1.21-debian13-dev, 2.1.21-dev

Index digest:

sha256:3baa99040db4729ba3f2aa39dabcbb7e0546c498fb5925ff3beb56eca7d04796

Manifest digest:

sha256:e61fc99db23a42338edeb296df4fa95798d67d40bd263fbe3fe8166c406dcc2c

Size

72.43 MB

Last pushed

8 hours ago

Vulnerabilities

3
8
4
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:da8c049d17eeb31dcc4241acd11a61bf4d5cf4a0f93129c77b01ee2640e054ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:e758ecf11b3877d6077fbe3fa18ec1d9cc454a7ee32c5d467839d8fd71ceb14f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:94660edc00aef20d99d8e87d0ef11d1a4ad5307300173a4837bd081d0168b599
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:627740987ca4ca2236721fd5b84cd1ac60ffc3af7274ea64ec9962662a6c8fb1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:85353fc25c18c423bda5242b38f14ed3eacdd1d6391bafe00f93c82e6afcc456
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:23df77eede384c4ed3a8c25cbbe266cb117030c7ed996263d4e6f5ebc21ab302
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:e5327321680836ef254cda48d01302c5049618c7a7de3b0b3af915cbda649bc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:fd6e83477bdf3c492f0fd3fc2163f33cc97688402cea0fb8c4a0c2db041d722a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:d8f06534c7fd6a34fc503e89f68ab620beacf5de3fc976c957382e8bb6158d34
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:f83bdc4e20c6aa4c58a567be24b4784c0ffaf9614fe354b965df059809675fe2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:eb79d4bae85488039af26a6b8a51e06d09973367e20496789e2545b985c76fd3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:267fbb5f620f22b7bc31859a193aea5f930340b83e0c87af096b59e76cee706b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:a6e5725a521cd2b3142181e45fc8a91009438b64383cf3826e49372e714db756
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:f480185c7778cdd352a50307591148a6c7240baa2df9dcc6399cc5a9135e2818
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:4cc5ace08c98aa3db88751a53eae58f56080512a039dae111877deb75fa1dd03