Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.90-debian-fips-dev, 2.90-debian13-fips-dev, 2.90-fips-dev, 2.90.0-debian-fips-dev, 2.90.0-debian13-fips-dev, 2.90.0-fips-dev

Index digest:

sha256:38c45c220102f52f0df7580ce5ca48fabc48f76d1e63a9d478c108f23bbb56cf

Manifest digest:

sha256:07f269908bba08a866a9337ff3f93922067aab58146713a34370590f063b659b

Size

51.78 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:7ea5d60025ef77e454826d3f8c25eb6376d022215896e7066a84461b70a65746
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:38c748cf3da16dff8dca21655e22e0ba1097cd2e319d8c0b59534b425acc5147
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/azure-cli@sha256:f4723b0146e2477719a914092cbea4400c089e19905485976702504f90c448d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:4c6c94803b08d08557713fd4a78f574d92da5ba025a05e305a58705f5171d8a5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/azure-cli@sha256:47c217ff4e1498ea40639545f29bbeece3a38a22e99f03d7f6ec865c61b1e057
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:42ffd9e79bf7d6b74b1ed81edadfdf0eea327ec8422449b848906e90aa891c8d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:f9b8857b16b9e78449ff71083ad0d2035be88427da1e964a3af4611ac3e433ec
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:a911dcce28f36dd5c193710243c89b3c214b4c5ff208d3b94666e65e8346b917
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:1ca9df0a1bd250d50e16d07cd495b480c939ff03b4168541cbdf63c72a403f1d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:00b81e755e8ec7f0d270a28f2e1fdbb7778c9dce253bde45fc1689a883f1a2d0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:80fa3dd9c785f85850536bbd6829fb6e634c4a1d539e93a7459f8b1f22267bba
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:0c9a6d3d0092f1e7fde49a25c221828cd69b00ab3bc854bc44c8f443399f38b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:19408f3e3f64a378156a4637b32455d571a8f16e1a338a6c387149bc1b720632
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:d17834471d832cfb55b6bbfb1358b728694ba30b6441c2843f575e9943e5b8d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:1d14ca314b9c4fe10e82fc5879a8a793775570962d201e0e3f5f395314c2d3f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:1661fe544d803aedc3b6134d9acf885bb8946fcb31bc9fef3de2294eff96d994
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:39e8f304d414b2535879c512158415cdd9fb1005933ff3d6aaab58669eeaf799