Sign inSign up
amazon-k8s-cni

dhi.io/amazon-k8s-cni

amazon-vpc-cni-k8s 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.23-debian-fips, 1.23-debian13-fips, 1.23-fips, 1.23.1-debian-fips, 1.23.1-debian13-fips, 1.23.1-fips

Index digest:

sha256:641105d382c92dbdf0a6238fec0f1c83a082893f55d1a3b356bbae6373bd03b0

Manifest digest:

sha256:8415edfcb4f45da8c38af20ac0981fed7ae163bfc31da9728a93703730f297c3

Size

41.88 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazon-k8s-cni:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazon-k8s-cni:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazon-k8s-cni@sha256:df76f741e411b9bdc75b3005e41e4983904a20176339466414ee6754bde93a9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazon-k8s-cni@sha256:77bfaf51228c2cbcfd3617716fbabf295957e738e3ee370d4f68a7366f192fd2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazon-k8s-cni@sha256:ec5d1af5b9a5cefe6975ac1f67079c073c7ceef707930ad8f00dca5661eb678e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazon-k8s-cni@sha256:da2aebc175b63cc8037f7d1a817475e1f223ec5aa68cba62050a619091389e73
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazon-k8s-cni@sha256:509e8ea5352b018b401db266d1d314e04c3c038619747413bc082baad2a575ba
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazon-k8s-cni@sha256:5facf3454c41927e2fa8b49fdc28d50fcaf077abf36db0c7a78d60b5a23b7d3d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazon-k8s-cni@sha256:9ceede89114213e0fa29c801d726b08b90f755b1fb1693889d94877f94e0a0c0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazon-k8s-cni@sha256:a855cceb2db89fb2fceb3e1fe928b4add6ac3789582c0f193c42e7925eada002
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazon-k8s-cni@sha256:45f488ec11f5796500d548a6f8cddcb9e26b28c646b486a8ffd68963197c6ebe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazon-k8s-cni@sha256:2f1c05dda9f7008e2bd51b4b328a4659faf924ebadf83ed437a9149397256351
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazon-k8s-cni@sha256:0c0fcdca13beb9b5f1929baa045c614dabe279e4a6f95da93b1f1bb7c6fe6a14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazon-k8s-cni@sha256:5f1faba06544a1841ce6664bb39de9cd39fbe327dc3fa4dd73f10690aacdc592
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazon-k8s-cni@sha256:3ed58c692c4ad7d70be1a9cac0b9e757ce8ae414ae4dae1325d17ea5db0f6566
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazon-k8s-cni@sha256:e864b3a23ab87e2fad6f652cd5746f01ef79f34ad55b7f8dc16941308dd6113b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazon-k8s-cni@sha256:061dad150fc1572f9d26f757890d16df0ee18997210d5e5c0bdb1d995bd0ec49
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazon-k8s-cni@sha256:8e5f8ac50aafcba243b58b71337ea40df010ffc9f9657d461999f31e169ef8ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazon-k8s-cni@sha256:5cb7502fd8767b1feab10f8c374babca5f2334f0ad764a5674a6d3cdd6ed1bb5