dhi.io/certbot
5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev
sha256:a1437212f34076eb00f87f34154c51e4cf84381d5142bbaa7d13dd01cd9e1b67
Manifest digest:sha256:f820f0adfcdcad340f23b661229b0d44672021f264062c3a573cce0f857e8e77
Size
37.81 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/certbot:5-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/certbot@sha256:ed18b576fbc6c06e504ead43b1b8692d0c7a4b8b3296c9f273125814eea5399d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/certbot@sha256:7bad879c148685a32ac729ab5be10b442c8650efd8551123a4aa459382f5d73a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/certbot@sha256:aaea830ff4ae3fcccb0e40c8f363c0e8d7f041c2f23bfd80f270f24957913a7d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/certbot@sha256:f569cb1d55950edd59af84a8289b479e085316a0e2bf667bc7cd9701a236b245 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/certbot@sha256:03da18fbdb1891ba08d465d4a18309a9c747a46310e69d351ae27f56ce788c9a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/certbot@sha256:19ff2c537132065a91768d28f51c08be358f59472df3e5673a1ac21772f1b9c8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/certbot@sha256:d6bb152d06666aadf8b3094d7d56e8e6ba6f24262465176e7472190ececa6fef |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/certbot@sha256:bbe1ce5092645a38dbf12f68b8d004491127a1bc8c004cb4b8a54d1647f73cc4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/certbot@sha256:63600a5f566b3e6e317046169dfcc72a86963ea9ae7e5a66b90fc3fe83762ab2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/certbot@sha256:2350f4a7b4e65f2de734114547b964f93ccd39e11b73d188a2f61c101c5c4d17 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/certbot@sha256:cd558b3d5d5e5dd90b2a2423cbcc060a1544c60378c32e000cbc893cfc8e1b2f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/certbot@sha256:bf189c54186ceabb59953a8b39d426a405bf0834402e21b98e0602d929ad1c38 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/certbot@sha256:1a44cf6b90a85f0ffe42ceca33c9d01d76c0614ad030792a00231e81dcdb6271 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/certbot@sha256:badbe5772c1c949db222a99bfe40fc87dddfa29cb5bc9df7952af4813142a4cf |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/certbot@sha256:050179e74b622124472c1fbbfddaf7d3f00092b0448bce74a56e4e146600fd3f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/certbot@sha256:80e312093e352d73cd2c98fe513d3b5a7d2e3d91d16a8bdab10bc6e4d57a0cbc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/certbot@sha256:935b1f2414f85239248c4234b54e34e9de7b573cabe81903109e9cfce856d480 |