Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.4.x

CIS
linux/amd64
debian 13
Tags:

3.4, 3.4-debian, 3.4-debian13, 3.4.9, 3.4.9-debian, 3.4.9-debian13

Index digest:

sha256:2d31439788d0c292ea577193e200dbeabb0fe8e304fbb0f56ab2588a2c6835fa

Manifest digest:

sha256:88f088a6d0f213f2db5cfd1048c5af833b1d788aba4cc7c35beffda804eb57fb

Size

115.55 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:3b0cbea902746d2725f21bbcfcf33ad312c65f8419e0e8a2fe565dca929f573e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:27e87dbeea0a298b981a00a29f0313caa583ab53231469226c1a69118ed583ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:7d1542277f5a620efda07d5bf4bb71861a672b77d58c4c86fe4daf4aa316dead
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:9d3b24b928caa3999c370374bc4bf8d5ae6d9d1ba5804976080a5e8b85266fe8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:a73c7a6b8f17fc156cdc2d9ae5d31f957a877432c6be46988fa6986eb0dd8e96
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:6bd808e0e6d5b0c5f2aa9ccbbe7703af2ac919d7719424100a5e23112d02789c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:2f23a9441bb758b3b9f74a6001c52d78e9f92a03f04690db2969de0eb6f22774
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:b35d584c85de199b9dc66e5fd0740e239c9b641c6bb9ac8e18e68bcd339fa0b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:260be62b162cc1809615355b8dd1ec88a49a8b5e1d9b3f1f5fe7cf7239c36d77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:728ac24121680b01d762b623c12e49deb858ba06d548375012f96961bedcb953
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:1351c5742e6b5981ef82fc28181aff89d780bb96a2743be69cc3770b77167450
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:bd3c1e0e0359fc141d4ddf4516378752242a1fa63ae91101f7f0d1858246c120
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:f962b0cd53810bd67e5ab4cea69dcf2efe2111af414f9f92d68e13303daac7a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:49d0fbd1aee033e8ab1597b683600aaadc484272bb5041fcf871116b1c288ee0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:d89bf6131b3c06c5de3fe118d39df2ec60cd7bdc11402736c260ba780fcfc56b