Sign inSign up
API Declarative CLI (ADC)

dhi.io/adc

API Declarative CLI 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.30-debian-fips, 0.30-debian13-fips, 0.30-fips, 0.30.5-debian-fips, 0.30.5-debian13-fips, 0.30.5-fips

Index digest:

sha256:f8fa52f76926acccf1b9243f37cc566b205923457a0a48cf2a7c90ee8de43e27

Manifest digest:

sha256:bd2c403693b9b8763b81a8087da524a7c78ceb0a43da7e85f848c210e6d1c734

Size

42.66 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/adc:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/adc:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/adc@sha256:1c838ed408ca7fbcb8921cb8dd89dbb8b1587b213db60565b8c7d7faecd403ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/adc@sha256:4b69e646a1f878ccd89d179e1b885efb4e297326ab8c9f7c1dc50cdf97420b03
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/adc@sha256:9b0b2b2d510223c9d907847ebb4bd7606b8178bff5e50b891d6c307a8a10c49d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/adc@sha256:34bf8a704a687c9660686d7d1d48558f8593ecb150b79ad356b5ee568a06c673
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/adc@sha256:130c5a02a3f6d9a7d23eed1f6148a1e28b231be7027f468e9aee063ede6fd43f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/adc@sha256:9c9b6da0cec54254c40e18404f8ed73b5daa0d4f6085a7d41bd4092267fec141
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/adc@sha256:24e4d2844924a2dd215e0e71eb610d22fe160f5bda23a15898affea089d330be
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/adc@sha256:acbb7e835c72f55dc79e5225f8c5de2033158514f00876b730b1989f8ba21637
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/adc@sha256:c6d7d7508510c5982b9aedfb85851dbf870f2f84c3e7693d6303a40f07e3f1ed
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/adc@sha256:1fb02db81d5cd02d67c3e2cacc5775c63c07b6d44007b50ce04e286f7a0d7408
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/adc@sha256:618a05c6a0e22223d6e8e028ae6172ec8cad6793f1d98c7d153011d2d6d4d45e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/adc@sha256:fdae6f43d0a416c6fda1f45c02eb0f950ada5343e5bf256b95cb9db63c5b9485
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/adc@sha256:a366f37a92f42bb75657507009aec5b36f6e6c6e2ba15d868ae6e48801c01b45
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/adc@sha256:eaed87ff9b2747b4b4cb0f4ce13b761fc891960e54570cb1b8d4188c8d8275a2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/adc@sha256:ed882eae407fef860bf2795d8a8a4c53e7480fc165b09c5cff1a9fd2fc7365fa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/adc@sha256:05bf7f1cab98d124082fdef1ef23b62abcda6e10b5ce91510e44c7dffdd8853b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/adc@sha256:6b4b0851697a5fca5aea65949937494ffcbcd69ea14c9a029e4db543a70caf7d