Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.19-alpine-fips-dev, 2.19-alpine3.24-fips-dev, 2.19.0-alpine-fips-dev, 2.19.0-alpine3.24-fips-dev

Index digest:

sha256:f5aa390b07256d115e66f0f44fa31fd43c0c8d87c6cdb512e93588bc0c42ec2c

Manifest digest:

sha256:9766960b0f2d9b231197650b6759d4a40c616ad37706060b2d6201aaa9e266fb

Size

27.43 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:7adf459bd6c7ba3cab361a2a8377c820ecce972d1fe71247079497ff454c809e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:75f2c6ae05fda1a4267a10fece4674241ef57207f5b70be8132823e983c237b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:c2a589ded23d1d49aaa2d15425fb1054aedbe85398b0fddde9ebc7b20b448531
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:985c98ee3dfcb90506e37e55d448b674798080dfb38890bf5b48e946d714ea06
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:ff8445929f14364879d25849d9e96514bef018dc977b244067e6f7c02eb981cc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:bdae58aab1911685c5bc78da0f23b015f15115e1ebc9822fcb982a8ff227f739
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:40c963835b3efd939c040d388c2ef80cd0f5dd5245583510e731bbd60baa7860
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:e421af54f17353fd87d1b616790ad89834b4dfca88086e366b8167073ae5fdbf
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:947aa2da55d729201c82d8227fe3bac8d93ec5be1c99476a4ccd07e33a066c0f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:bdc308aa1c1eec868458e7283658ea6f06aa909964d44e8844521c4a0db7a369
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:1316a5af5163e435c3ccb7e47288a5a17ff6ebe8860653da69d9eb09358ade07
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:60456d0ced357d6b80461a68b42e5639ac1c5997b5dbf2cac5421e5dfd2f2e97
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:e42661665cf161f6eb54e0d58438d0e3baf00b7ec424b47e0fd8bf33dd95ccda
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:39b3fd45cc8a43c7fd42e8b62418ea5c24ba3d2a11e92dd338ac6bbf6dd89290
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:8ef50d4c972d04f1baa5214069bd5655599ab0a65c7de120933858b1ed434a4f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:ee0e4a20c8e69958003e93cd8c58514466c97362a2dfe70e7f3b7782f62304bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:c0c0fdac1f77afb2927e944018c17cf3d53fd20341ee58ddac63ba24c129242d