Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev

Index digest:

sha256:b43b2eb7c29d5a1d5810b5f5cf4200b260d4a02ae6a61b195624fb2f91da7c4b

Manifest digest:

sha256:b521df04283153147c12ec1a580553b3357ff87aeac8749835f45ef3563db255

Size

87.13 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:0c27389c58772b96694eaf9ab0786ecfd27d1254781bd60b89786fd259421108
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:9467ee197a0b6ffeab4df1c2de0229264484124163f8f493881861284d440f75
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocli@sha256:243ee36006ff1b4141ffa41a52aa732ad5566ea47744fadeb9794297c959f04f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:aa0e50d665d6f94644d7696aeb21096790829bcfd16294065f2e5a33aa24bd67
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocli@sha256:1ee194e3b1ea46fc923c7122c32f15bfc6dfaa2aa7bab86357938aca5ccbaf7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:6ef86449b39fdc59fe2566de08a03d8f32b4c4e6d4e93b0aac40d8a6c8d43084
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:a5150bc0748bc7e767c5f2ae45bbfabe7b6ccfea1755c4444f4170bdd95c8366
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:cec74468fc1461b5fb22d314af853a064a1a1f609303e9b35ef162998ca739a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:702c14517d3b518fbd1e3f160c4920a03959f578abf0a3b83f4ee8558ef91772
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:271faf941560d1df8b1ffbc66f515f156e3437089a222abfdbf5f08bf5594a7c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:533529f5352b0d4e0ae73fda645c61d8325422dfac8d921f0ad49f99e46baa2e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:9730d0cd7c74cd6282005b6ef22d81da3623ae0bc5dea1f6911514b62a222a6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:2afa367d08976eff658ba5aa90d747165e718ed273bfe9d91c67688cb13c9f08
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:63bb689f3e1d1e2b333f7454f89970af603627ab61d0d1703f47102c588d19e0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:dc7d32983155d047c25bf6b17ebc9f8b9b77853d310554314aeae9e4af6b8b55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:5c453efa382433ad7914b8f0c688f4c21e45b06967d218322198db12a1a6c4bf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:4b38a6afab652c11402eaa85508d2f56e8ff3c6e3d5633516c21c2e440da484d