Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.90-debian-fips-dev, 2.90-debian13-fips-dev, 2.90-fips-dev, 2.90.0-debian-fips-dev, 2.90.0-debian13-fips-dev, 2.90.0-fips-dev

Index digest:

sha256:95dbbaafe6ed783c8c4f18628ac57695cb2435f26b91b01714aff53cefadc9f5

Manifest digest:

sha256:554835be60445c92af76da776ff49de8895c4156cd3ca146ba239d84b5775eca

Size

51.81 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:75306377b25ca6e294b52b0adcf280e9749c4f59affbc0fa6bfd12b31afcfcf8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:bb251bfa5d7fa22c10c2b128187e740a68ca481824eed4afc0cde842142338c6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/azure-cli@sha256:797e2a2d0db4e839fe6e0fd5d304951668086e98befc099c2f640cdc86f10d44
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:3a1dbd543db98a6a04eaf831641b463a321257349cd9dc1bc7e00af1e8e23bbb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/azure-cli@sha256:306280e4160591eff6dc3dfe3f4dd177c3fcffe48eeaebfc0bcb5af1663beef3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:d16d15bb0b3d4dea0941e6860baadda86218017a7904343c095cfbf97ff6d661
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:a140fad7cb5e939616d6cf1b5eb0794e737943401c5e4ea1ad16f5996f39626f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:c3e6a12ab6dece082ff05e22b8b934283e1908d6ff3153f4dcd73c870c330ffe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:5164d61cc5440e20c13017a77846268c4eb4637608ceedc75d20d6031d2763c6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:6a2aa9ab8953bbc7656d19be2c2591644cd383fbb660841b9c3e70dd8ffaa5d2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:e61079ad75b2fe777dd4e56216b219de9f8305c73909191cd9d43d8b0f75a2f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:1863dbfdf9c53efa0a312553d8e6ef6863c014831135c4025ddff77c76e99099
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:2e6b936d2cc45ea5e01504f9db90115f6e02ef9b7bb6a2c709899a70404a2e56
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:d99858e08bfd0f44e6f6022ee3b78f4bcb798f8c76385f1a84574c8503ca6b46
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:9224a375ff853b9e750f62007e0c6ee7aeab364bb107c99813ad409cf4c9b477
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:4569d6811e9a3b22809085a4a069554a1aab7bd25211ecd197b2fd149734d509
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:e7d3b988508aa8c6eee25bc9670f517806cdc4576d107dbe3aefa7b8a296e9af