Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev

Index digest:

sha256:8541209c1267a72ddde10c3db28948d4708f6f4600633426128bc06dd1a50b36

Manifest digest:

sha256:a9fcd047d83e325156abd11ad69ad662c4f69daf3da9b4997dd7e4f2bf2bdd75

Size

37.81 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:e505b059b291d7da3024b296255ba2f139bc7d488b2eb64ed7b72dfc801fff04
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:c19aab466d2f54683584906a8e66ee76f0ad28f5bd46db44af88f913705a5bb4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:a3a6571fdc48c9ee2871831aaec1f1683e214727428f19e95f90937f06d567e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:05d08a2a678aa15fddca7a46f3ecf16cc88451cb9f5ba0bd68f97293fa1be2ba
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:14780951f7c014abca8550f4b7ff0f7bcebdb6fbf01be6f3eb423b03013aa40f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:a1315bd80abe2e8ee3be94e55d9da3a6a4e3c383e725c44334e643a26e587b4e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:0f6b666fd4ad9f14dc10de713729fb48bf830c7c7e9848121ff7499b59e8bb31
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:4d49a976a001669ffd0a917306c9954348a71aa315410fb802556abd9508584c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:9f06c22da8fb1ae5d909f08daa45199b2dd0e93576d6df6818ee0033a8c46880
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:3079bd2f4e9667bbfd680c2e46575bdf74eab7e798a48e9d66c1ec3834a29820
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:0d04d862a35da7ecfe582f69af7e2c64b9577de0538b452feaa505c810130a60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:c64a94beda644003733eb1c5d37a53e3515b06843e779a3ab1e390a3c4bfa4a4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:e9d7dc3367219b12e8e49e87abd66310ce4913fd0b3b64efd595b8ca0876c9bf
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:fdf8148d821e84370e607997fefa7bef75a5b85a0ccab047fef0c51bf33ed923
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:85154e7991c8b039082c4de186621cfe5059a2e388512276a49ef7da19a7a78a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:d0ea3efcbe1533f93a405a57ae45e28391b1df4aa9e53a52650015c9677dc580
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:efcecfed63e70234b8b57b9a863d9582a4d56191221200a826258e6c25fcb00c