Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.5.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.5, 3.5-debian, 3.5-debian13, 3.5.2, 3.5.2-debian, 3.5.2-debian13

Index digest:

sha256:239d2c93b15d1a2a2cbb539a269e0c46e4becb16a448476c65ddc0c2c3ed6694

Manifest digest:

sha256:d3ea8671301cfe0f2684eb5b4a1c7a57d097a9622c9ccecb98707846e141f89b

Size

93.54 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:3114cf41325292b01dbe3f437da1d3f0d37178367a5d15aad7b89627b9de832b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:fa838b82924e15be974c62a3d005f769fc0be1d77c6b6b720537d1c3df7f45ff
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:8228e8493bab502c3acec6e464ac687b8d66f6c5561a7a6ceaf88b8e687dce25
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:67837d40cba243bcae88abea0b1e56a4fea41541634a5b9cc886aacb33fd73ca
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:0e13eb03c5767b1d97b57ac4a500897570ccc277a475904d3b0dcedbc68a4c20
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:a72f7669ddf418cb87cc1ca60fe8d480ff773208ea2ef275ba7cb2a1edc6a1ae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:357facf282122179c0f9b056db16b84b5f695f8706d20debe92d7c89a251a378
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:d60b54a7826d734ac588b6d2f8a593217e51330e6969cc75110eed31d55be323
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:e1bee228b274aa8ab125f840c662d5d1603252b8f3a8db3ecd4e6bbd6fdd5418
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:44ddd5c1e5c67865c3068d7ad909d460517aef90188e90ff6bb1bfe6ed995d47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:60be752f5308100fda29e8f1b924d71ad94c1fb50959c4d9757afa31308b194d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:c490b2ba0828af199008a40fe9862803611286cff55f3f30dc2c5326983bbcee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:0ad6adeec2ae8476dda513ef3e451033111acef87a656d04c1ffef978d165683
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:8d429ebaebad08fd6957241f00d3e85eea0c4d2515f47616fb84e817ade42a23
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:12a4a1502ea61ff7254b78fb0743f2488df98908c0919ac326a095c7960d7460