dhi.io/amazon-k8s-cni
1-debian-fips, 1-debian13-fips, 1-fips, 1.23-debian-fips, 1.23-debian13-fips, 1.23-fips, 1.23.1-debian-fips, 1.23.1-debian13-fips, 1.23.1-fips
sha256:641105d382c92dbdf0a6238fec0f1c83a082893f55d1a3b356bbae6373bd03b0
Manifest digest:sha256:8415edfcb4f45da8c38af20ac0981fed7ae163bfc31da9728a93703730f297c3
Size
41.88 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/amazon-k8s-cni:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/amazon-k8s-cni:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/amazon-k8s-cni@sha256:df76f741e411b9bdc75b3005e41e4983904a20176339466414ee6754bde93a9d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/amazon-k8s-cni@sha256:77bfaf51228c2cbcfd3617716fbabf295957e738e3ee370d4f68a7366f192fd2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/amazon-k8s-cni@sha256:ec5d1af5b9a5cefe6975ac1f67079c073c7ceef707930ad8f00dca5661eb678e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/amazon-k8s-cni@sha256:da2aebc175b63cc8037f7d1a817475e1f223ec5aa68cba62050a619091389e73 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/amazon-k8s-cni@sha256:509e8ea5352b018b401db266d1d314e04c3c038619747413bc082baad2a575ba |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/amazon-k8s-cni@sha256:5facf3454c41927e2fa8b49fdc28d50fcaf077abf36db0c7a78d60b5a23b7d3d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/amazon-k8s-cni@sha256:9ceede89114213e0fa29c801d726b08b90f755b1fb1693889d94877f94e0a0c0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/amazon-k8s-cni@sha256:a855cceb2db89fb2fceb3e1fe928b4add6ac3789582c0f193c42e7925eada002 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/amazon-k8s-cni@sha256:45f488ec11f5796500d548a6f8cddcb9e26b28c646b486a8ffd68963197c6ebe |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/amazon-k8s-cni@sha256:2f1c05dda9f7008e2bd51b4b328a4659faf924ebadf83ed437a9149397256351 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/amazon-k8s-cni@sha256:0c0fcdca13beb9b5f1929baa045c614dabe279e4a6f95da93b1f1bb7c6fe6a14 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/amazon-k8s-cni@sha256:5f1faba06544a1841ce6664bb39de9cd39fbe327dc3fa4dd73f10690aacdc592 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/amazon-k8s-cni@sha256:3ed58c692c4ad7d70be1a9cac0b9e757ce8ae414ae4dae1325d17ea5db0f6566 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/amazon-k8s-cni@sha256:e864b3a23ab87e2fad6f652cd5746f01ef79f34ad55b7f8dc16941308dd6113b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/amazon-k8s-cni@sha256:061dad150fc1572f9d26f757890d16df0ee18997210d5e5c0bdb1d995bd0ec49 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/amazon-k8s-cni@sha256:8e5f8ac50aafcba243b58b71337ea40df010ffc9f9657d461999f31e169ef8ee |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/amazon-k8s-cni@sha256:5cb7502fd8767b1feab10f8c374babca5f2334f0ad764a5674a6d3cdd6ed1bb5 |