Sign inSign up
Zot

dhi.io/zot

Zot 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.21-debian-fips-dev, 2.1.21-debian13-fips-dev, 2.1.21-fips-dev

Index digest:

sha256:0f573f11ecc5a2bb37856b2c6f8a4982d903c1a9459ed50f4727324d4e5fb540

Manifest digest:

sha256:7728a8e963a28b3c7de92317abbd6a606ab2e09470487f357b0236c8bf18da3c

Size

73.20 MB

Last pushed

15 hours ago

Vulnerabilities

1
0
4
2
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:eb6ceea119f8d194e72c80dc44d53972eab54c517804eed2fda09df5f0b78d41
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:8323f83d187dfa34560db2f18147bede6a9411f53bc0c5476f5ab87759457047
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/zot@sha256:4eb6178a7aabf722f9340e1f3962e624ad0c6ecdc9f6359eec494ea34b181d09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:0acbe0a8071790ecb62791cc9fb3facc19ea7381336a744121a101971ff88f3e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/zot@sha256:b404dba883469d014127348c4718c926d56493e2e8408cdcb257e7f7d15aed9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:a0bb2189c781675bc772fa182700b6bcb73e45c2832d8f4c88fd0ff4f9f5df30
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:8a095f5ed6f7eb79ccb422dc42d2ae9cf3fc08e8aa54346958bbee6017b86cb0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:b8dbe27ddefc80b271af4144a2c96a38207e1bf272b15581fdc29babdcb394ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:ae9eb725c727f32800511d3b99eb29ad0fea29b31133ba825cf6c094ba035a99
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:ae515adc40a6b8af128bd2cc335e4592de979b14f062c090acdfb360ca94bb53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:6a7dfce058274509f2ded231e9e2211199e4e6e2de03869ab225eab5afa37b10
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:fd83d247b37e9c776cfa8d16ce5d2e77522c62c1fadc6bb18cff5a8976d1579a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:41381d4e0da90d5b260e93c084b63a43e16e4b185252ef20ff680210527f8145
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:7d63ae2ecab021a3b49a18d9185b26652396a92ec961c3fe6e3901ad81ebbf28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:bac5954d41c96b637d5effdd7d747494ba35f67c8f4e3a63bec1e5444c81d48e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:d936c04243b96ec2b711b5e3e6dd968af6bb50fb300222044f7e3bf4ddab99bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:873b458779c28a17d4e2add10c485f11cb80be4a08902ca580387ac7865863fc