Sign inSign up
Zot

dhi.io/zot

Zot 2.x (ui, dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-ui-dev, 2-debian13-ui-dev, 2-ui-dev, 2.1-debian-ui-dev, 2.1-debian13-ui-dev, 2.1-ui-dev, 2.1.21-debian-ui-dev, 2.1.21-debian13-ui-dev, 2.1.21-ui-dev

Index digest:

sha256:c589c6fecde6d29dc7af2d1e7ffe776db543e9122d0b601cc10b87eb8ad474e7

Manifest digest:

sha256:8e8c1e1d93dc292344afd3353d75c96fda5959f7a447ac551fc8cc7fcd08eb49

Size

73.45 MB

Last pushed

13 hours ago

Vulnerabilities

3
8
4
2
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-ui-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-ui-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:e0ecbc0129c43be518e6823164831f8f0be82fe480b6f7f45289b51cde7d68c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:5bac6803bc3e17e3d6fec553d919b761b02a9a9cbe4b40d8cc901c70de9db4a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:d9775a8626504611c156ee27300504b9faf6fe8f084bc74e2bba99567e6b5c5e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:12c756a0d215048856ab848bcc4188aabbf926e370624199dcb170ba2f8de857
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:e47121f995462650f85b102809a95f94b96b702266163c15762ca0dc4c359665
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:c3a069bf21a43aca26ea9878319ceab62f9394641a3ebcf1684c1832f4fee294
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:4fce8b7a2645c20d5a1fef5cc34180d7a4b4ce8b231a88b3a93a971afedd8eb7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:3c65a8e0dd8acf233afcc5a72e527d105183e897fb07ff9c2c48076754a959aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:fe9d311631d46123b2856cc0cd6aab0205df88c0c09e6ec7e2aa6f89877e0eb6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:61861697fa84a66bae3020c1d16c115cff95e0a3b071b64d03f9abe04b2f8ff7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:f20e30012b79ccd09f199c7e4dad82c0d79ea2231f1d79b618e069674cf95bb0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:ba0131bdeafd7d47dd45314b61708ca686f73c499db5cd7091a68f35ece8e3e2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:2f37a3071ff7d782dd372880ff6943c10adea2a9e8fc16c878bae6055e620ba0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:ed35aaeaa271734ce3d8324b7c91a61863319df89273d95203d87764bce4dcbd
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:86c3d3ef012b516a920bfc50ccadc4d2385db45a32f942ee882efed74718d564