dhi.io/zot
2-debian-ui-fips, 2-debian13-ui-fips, 2-ui-fips, 2.1-debian-ui-fips, 2.1-debian13-ui-fips, 2.1-ui-fips, 2.1.21-debian-ui-fips, 2.1.21-debian13-ui-fips, 2.1.21-ui-fips
sha256:76cad1f5efa6acb205b11155e353dbe1419e2fbb30a6d37a3fbde8a3d1c0b7dd
Manifest digest:sha256:a3eba8aafaeceb9d2fb54ff6b7bf4bd3ccacf437e0f8ca7db121c43d6b5efe3b
Size
58.96 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/zot:2-debian-ui-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/zot:2-debian-ui-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/zot@sha256:f0526079fd9552aafea92dbb34001bcd9d61612174434bf52445db0372fdd972 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/zot@sha256:ef57aab163889045b76e7c7d6eba48e6c038343f1d0b3a9bc0309039a92025f2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/zot@sha256:0e300359e210e4cb4f0719a8e1a0d074a97e89390703b8c5f601ac3e9e791d7b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/zot@sha256:9aa5d1373f01526fe7d27c1ea595501e014c36c2d95b4a01ea9130bc19e819ee |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/zot@sha256:219c8431bb83b912cb76a9faf9249ba03bbf662bc6d97572ec1733e9ad3e06c3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/zot@sha256:a9e63662e7ebe0538d07709572d9c3840b81a1048bdd45508d13ff96922f3501 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/zot@sha256:1b51d9d4144dca6c36aa214cbf8aab37de09f6595a35c6b0b859f778c8414798 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/zot@sha256:2e8db6eb6b29d5c8668c5629992e62607da7546d905c429147210585fa27a5e0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/zot@sha256:ceb07e45aeba0ef82502ef8c1c44c65499722410081b43a0f8d602af53399fc6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/zot@sha256:44d8ece07388107d2da2baba415f9b2162af9aa6f7e44b04a8c6047e432e9c92 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/zot@sha256:332af5ba0f632656ffcffde4e10f3757286599e215fae9d0e31dad5d43059fce |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/zot@sha256:9d1f7a92d7d35bb69840aa09aa110a8e9079dfe26bfdfb1a3eb07e82010bbb6c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/zot@sha256:aab7c061c5a57f1a9827207bc30fbe3ab1f36a61bbaf1cdd88be56668a31f152 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/zot@sha256:842a76b8d2c316e9d9e4d814466dc1f8ab1a366c9aaf64f5fc5d23a1ab88582a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/zot@sha256:5df4947cd461838f2dee6f18928e754bf66c7d1e3e4052586d5b9a3091c5b2ed |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/zot@sha256:976eb3eaee675f0ea7d6855a6f8597a92c0ec32c718350f311a001ad42b92c7b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/zot@sha256:3f0cb444e56303c0c2962421d0e81eb65580e6a2460f491cd1682536e95d81d0 |