dhi.io/argocli
3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev
sha256:b43b2eb7c29d5a1d5810b5f5cf4200b260d4a02ae6a61b195624fb2f91da7c4b
Manifest digest:sha256:b521df04283153147c12ec1a580553b3357ff87aeac8749835f45ef3563db255
Size
87.13 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:3-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:0c27389c58772b96694eaf9ab0786ecfd27d1254781bd60b89786fd259421108 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:9467ee197a0b6ffeab4df1c2de0229264484124163f8f493881861284d440f75 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocli@sha256:243ee36006ff1b4141ffa41a52aa732ad5566ea47744fadeb9794297c959f04f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:aa0e50d665d6f94644d7696aeb21096790829bcfd16294065f2e5a33aa24bd67 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocli@sha256:1ee194e3b1ea46fc923c7122c32f15bfc6dfaa2aa7bab86357938aca5ccbaf7d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:6ef86449b39fdc59fe2566de08a03d8f32b4c4e6d4e93b0aac40d8a6c8d43084 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:a5150bc0748bc7e767c5f2ae45bbfabe7b6ccfea1755c4444f4170bdd95c8366 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:cec74468fc1461b5fb22d314af853a064a1a1f609303e9b35ef162998ca739a6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:702c14517d3b518fbd1e3f160c4920a03959f578abf0a3b83f4ee8558ef91772 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:271faf941560d1df8b1ffbc66f515f156e3437089a222abfdbf5f08bf5594a7c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:533529f5352b0d4e0ae73fda645c61d8325422dfac8d921f0ad49f99e46baa2e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:9730d0cd7c74cd6282005b6ef22d81da3623ae0bc5dea1f6911514b62a222a6a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:2afa367d08976eff658ba5aa90d747165e718ed273bfe9d91c67688cb13c9f08 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:63bb689f3e1d1e2b333f7454f89970af603627ab61d0d1703f47102c588d19e0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:dc7d32983155d047c25bf6b17ebc9f8b9b77853d310554314aeae9e4af6b8b55 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:5c453efa382433ad7914b8f0c688f4c21e45b06967d218322198db12a1a6c4bf |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:4b38a6afab652c11402eaa85508d2f56e8ff3c6e3d5633516c21c2e440da484d |