Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.19-debian-fips-dev, 2.19-debian13-fips-dev, 2.19-fips-dev, 2.19.0-debian-fips-dev, 2.19.0-debian13-fips-dev, 2.19.0-fips-dev

Index digest:

sha256:e701f402e6089aedf2924e1194d16c714fe8fd649b62d7ab61f17e98dc98f308

Manifest digest:

sha256:17280955314ea5b8a066d91d87197ae10d90f666a87d99ed88cfa85470b0e6c3

Size

46.72 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:d150ca655223e4301d38478779c1f105a54354867685201179cfcdcf9b292897
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:918618f1a12baf3c111c633fb89f6665ae876465911728dc3013cf1e3564da00
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:36a301c9896114146cccb94c31c5f39c896198d7a9214c067bf6a297333ab61f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:ff5d4dd0744dfd9262c5a6fde2080e993408bc78c2569696ff4525560039c41b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:0a1d6c24540b1ec173b22bbb1b4e58a59f583bc0e996d06127fe5a21337f92be
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:bc657ee2748664d7d2889616e91979bf0c212f6e4f78239ec04fd370d7ca17a8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:a474f0f5fe6bdce85445dd6ad47a175c5d82dc0eaf28a482f35a5947748db813
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:a8333f2d44d353a6c149848192799beabfec00ec1782e7e13018eb94a465c59f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:1819a0b469a07f1f3ff8cebed75a3172f76a97ff5acb2e72a7f9a1d06bcc72d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:b1a94643e09be10c94603fbb47ed802e05f13f70b503e9e4aec2b8fe6056aa99
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:861afbdea26c493cd1f8794584397bdf3cf9ae3c2482876b0943dd8dbd9effa6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:29e7329885442fedd13ac3c51fbd30919bbbe9189213185667085ecfc73882c5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:c8757920a89057c2f9398d8d7c12ad1c9f10ec6fbf5b9b0d3f3cf03f2211d3d0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:8e4c5331e115e1952c8b4c6e7603f109e413ed98512dbe9b92d86eefffe77a40
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:5f0ccb1eccb9963b19f8c3a20cb79d263bbceaeec58e1215826115c8f55ef937
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:276fa83b4d91c091933ee68c3153a2dd83edbdf2d88b8942ea77195386b9bb99
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:b8876ed89226fcd10e2e71bf36f16fd719b653d2532d840708ce1408e2fbca5e