Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.1-debian-dev, 3.3.1-debian13-dev, 3.3.1-dev, 3.3.1-python3.13-debian-dev, 3.3.1-python3.13-debian13-dev, 3.3.1-python3.13-dev

Index digest:

sha256:c10cc6c4ac45d83f9913fca2ac61e995d706c5f0a0b4a692e37030f9dbd2af18

Manifest digest:

sha256:e5cae614ed78929bd76a12178d7b077660836c83282e330c956cc7a287008889

Size

78.13 MB

Last pushed

3 days ago

Vulnerabilities

0
1
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:1b29e5d98ec3791222fbbf883b2271d0e01710e8ac33380e53116951802dd6b1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:852bcf9b7372789b7a9bcca2397f75d856750e697e2d33b66f81bb51c094a430
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:17845b6fc36f8ab4d37fad0c0e1ae2579072e06ceb16ae048df07a6a316a8408
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:20b171b5998585923f05f6aa5ff2e50852727e13d0132b9e90d0dfcf9857869e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:38d0f7325609c872c41de2c54e3cb3aa5ee4d8303088ed11b6109281763d0da5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:2ba14825a70e8930935521e68ad2e1c67d390481d5e7c28af1ac31edd4db7b34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:529ecd082724b68cf474c6386c16ec9fc21bce30294e3e115cfef1e1623d1205
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:9a447c6147e259ca249995e0f0a8e7a2d0de6c55a560b49328d2d03df49e7934
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:a9cacc0a704036ba3ef1caf522e718037298eeecd04afb2aa83a7ec6b5af73f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:56f346388bf917c29a356e6cf141e67d5616483c4df570331c18e6323042e741
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:c12f2af2249140a388f2c9d4bd032ba926b870a78e2dc2b9859d5951151acbb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:2d79b5db5615172d390a72bbd2a40fc423fdda8c0b18b7531c3005eb1376fe30
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:3b0894b7fdae1a2b8ae2d7684cf9ad1cedc039352a9f699f68dd8005c3fdf309
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:ffb62eb21d531aeb198182fe9dcabf26395a6192c0aeb90932a84e22b6906ac0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:48f48113f93c037c5e9902bf6bd79caabc6a529e6597091a3120740ca84bf006