Sign inSign up
ChartMuseum

dhi.io/chartmuseum

ChartMuseum 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.16-debian-dev, 0.16-debian13-dev, 0.16-dev, 0.16.6-debian-dev, 0.16.6-debian13-dev, 0.16.6-dev

Index digest:

sha256:d6f29760cd6fa57470a67e167ae654090e64f2850606749b5c50741b471e81b2

Manifest digest:

sha256:11e3f1d27c66bb01c913066b19cfe015503c26e23152fe7d9a3f6421686ce5b8

Size

42.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/chartmuseum:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/chartmuseum:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/chartmuseum@sha256:a32d506eaf9c5d17ee275cc89652c72c95b0f82f309ba389a945932823a8ac5e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/chartmuseum@sha256:3a5acbc27d132c9fe39c8535b765fbaa948d5273f0c1a8705881d2059b6229f1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/chartmuseum@sha256:7ecd404982c70e43d64ab9d56f9b3cefeb6848d03d4a4808a0ece5b1f170ebfa
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/chartmuseum@sha256:8b79be0c5ea2579906c5ecbcfbade7f17cbdbe5b9a4763084491c27a6263996c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/chartmuseum@sha256:1eb4054fdceecb3dc9b3b6ab14e12e6fc121ee93ec25e4bcbba5c62f20a4e323
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/chartmuseum@sha256:8309847ae7e3063d7b3bb82161fbe765389940536e5fda267bf8771c53bd9251
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/chartmuseum@sha256:3d3cace6be83ca48e3adec03ffa11201b0e3b1056ea8523eb00f8d3319214956
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/chartmuseum@sha256:081346308004c0fe8cf6460737987ae4191cf1e7f312a1ba51abdfc5629970a9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/chartmuseum@sha256:6006423aae1a41cb9717e61c01f94db38334d161b44062ead178fe4250ea93fe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/chartmuseum@sha256:8c7d6ba3c6d41e1163dd7541d39b3dee41ca085b00d0a8390b67d8de83af2b7f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/chartmuseum@sha256:2b01da05867b69679a51cbe99636cdc1b27839742bde95b6ecd298fabc567dc5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/chartmuseum@sha256:ca13845d99269b00cb4c5004f42161f3b497e9ed17e454f8004f02cccb9f7aa4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/chartmuseum@sha256:48a388c3f1c057664e7f74b34e4116c49a79b19dc3a33021ecd0f6a33df5fbe7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/chartmuseum@sha256:5b0fa1770a421e43862c6e680c68a93618871a2fee6df332eb8f894c3d067483
SPDX SBOMhttps://spdx.dev/Documentdhi.io/chartmuseum@sha256:b03bd0e9813845d607843ee44f9b12aff21b16f440e90331084cce67eb0bb581