Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine-dev, 2-alpine3.24-dev, 2.19-alpine-dev, 2.19-alpine3.24-dev, 2.19.0-alpine-dev, 2.19.0-alpine3.24-dev

Index digest:

sha256:b4fb375069b260b0e070f72e808b7ca95b96db17360b4c1cf3c93d0cd6d045e9

Manifest digest:

sha256:85cfb776cae5a41f667c43d8301223e4e892b1026215228bb75acd251e207360

Size

26.60 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:7154552875180cc3090cfe0d5b138be6fb5cfa2afc6b50c431e3724a4d50fb09
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:c40af5c58ff25fe47d33b4180560261d43ec708393307681c7e898ed202320e7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:9f801ccef8b36b080f901aca6706e2fbcbe1abdf944386e56e942fafbe3fc042
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:b75f82f174481f6774b53c4b83e5a6e8cef15e1b8d35be1fdd7423541b2e7e8a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:65c92bb629bde05cf2860e499f4259acc545ac77a6eec78c89758db59defebf5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:c5335e8c46d039fac4f0ef35e25335760514e8fc9b8c1ed9cb3fedef09ee7364
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:427a11d47e1e3c67f30b92fa05e104f653a3b432e1380112e497e2659579a8aa
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:77221e2949fdae7d2ee2a89cf94a61d4e87d63031f4530cb94694b8b1725e78f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:d54786e3d5b95853a3f05bd7146dadf371e80480defbed1b0451c37110e054cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:2c5e71bc931ba351921f41d5aed3fce8563453b81377a0ac3a5bdd2f3c19c81c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:f9513d52336628c3a25019eeec80c2e277fa5238cc67965fb62c28f542878825
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:c4478d7f9678fb64cea2a5181cb47809fc801e6a1bf50f7ca4bacc1f3c310da6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:f12311521061fe07144b341cc0e6908ad7c0b528c78e76f267877116ced6320f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:be6cfb990ad46749ee89c48c39a48d75ad23b01b6cf1ae4d7d51483269269450
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:07f00f272448db95597f09dccf6427269ce2513443b18002dfc756b0c3231cc4