Sign inSign up
Zot

dhi.io/zot

Zot 2.x (ui, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-ui-fips, 2-debian13-ui-fips, 2-ui-fips, 2.1-debian-ui-fips, 2.1-debian13-ui-fips, 2.1-ui-fips, 2.1.21-debian-ui-fips, 2.1.21-debian13-ui-fips, 2.1.21-ui-fips

Index digest:

sha256:76cad1f5efa6acb205b11155e353dbe1419e2fbb30a6d37a3fbde8a3d1c0b7dd

Manifest digest:

sha256:a3eba8aafaeceb9d2fb54ff6b7bf4bd3ccacf437e0f8ca7db121c43d6b5efe3b

Size

58.96 MB

Last pushed

1 day ago

Vulnerabilities

1
2
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-ui-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-ui-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:f0526079fd9552aafea92dbb34001bcd9d61612174434bf52445db0372fdd972
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:ef57aab163889045b76e7c7d6eba48e6c038343f1d0b3a9bc0309039a92025f2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/zot@sha256:0e300359e210e4cb4f0719a8e1a0d074a97e89390703b8c5f601ac3e9e791d7b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:9aa5d1373f01526fe7d27c1ea595501e014c36c2d95b4a01ea9130bc19e819ee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/zot@sha256:219c8431bb83b912cb76a9faf9249ba03bbf662bc6d97572ec1733e9ad3e06c3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:a9e63662e7ebe0538d07709572d9c3840b81a1048bdd45508d13ff96922f3501
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:1b51d9d4144dca6c36aa214cbf8aab37de09f6595a35c6b0b859f778c8414798
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:2e8db6eb6b29d5c8668c5629992e62607da7546d905c429147210585fa27a5e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:ceb07e45aeba0ef82502ef8c1c44c65499722410081b43a0f8d602af53399fc6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:44d8ece07388107d2da2baba415f9b2162af9aa6f7e44b04a8c6047e432e9c92
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:332af5ba0f632656ffcffde4e10f3757286599e215fae9d0e31dad5d43059fce
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:9d1f7a92d7d35bb69840aa09aa110a8e9079dfe26bfdfb1a3eb07e82010bbb6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:aab7c061c5a57f1a9827207bc30fbe3ab1f36a61bbaf1cdd88be56668a31f152
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:842a76b8d2c316e9d9e4d814466dc1f8ab1a366c9aaf64f5fc5d23a1ab88582a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:5df4947cd461838f2dee6f18928e754bf66c7d1e3e4052586d5b9a3091c5b2ed
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:976eb3eaee675f0ea7d6855a6f8597a92c0ec32c718350f311a001ad42b92c7b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:3f0cb444e56303c0c2962421d0e81eb65580e6a2460f491cd1682536e95d81d0