dhi.io/dapr-daprd
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev
sha256:d9bd87f9d78b7d0e5c633f913d3411af6c7f14b23389618aef926ef65e2416dd
Manifest digest:sha256:3a5719a18e4124005f575a5076edf40e55a3909ba37c6bafdb80ce9f5569c4a2
Size
130.25 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-daprd@sha256:c7b2f9a296e213ad59188c751e89005110893e89b04f4ed38abe9620752c07c0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-daprd@sha256:4d9755fa43647ffcef9b3471fdcd553fc6276c858bece8759fefec4f46d1b6e8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-daprd@sha256:78d46842891a31af0bdf520d511b1eb4c0a06e5ff39db87b4bf46047774e2d17 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-daprd@sha256:6f83b63e600146dd9b9c06d716911a8609b24f33094ee82ca476be1c58c746d5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-daprd@sha256:ebb5dbf76d84d175fe6a97d1951900dd22bdd1b0e709cce69d715245e0ef1285 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-daprd@sha256:51edbba7a1e21340082b63fbb194b1916bc321f0cc6fda820f5cfcb4164da79e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-daprd@sha256:4bb90affa429e43b2925fcd7b4c5f5bb540b087048377881f3b85d8839eb2df8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-daprd@sha256:75fd815e0be67141ebca65a989a6ba0264eeb950cb7082c00783230f800abbe0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-daprd@sha256:60d11d877ea17c8526d98c927f08de5bb6d01034f2bd2534853c4011ff057926 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-daprd@sha256:0bca9b2ebbfeed9bba9910198a26a4f28a55f105381ea683c32dbdf2ce9147bc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-daprd@sha256:ca9fe051f98c326be36cf84737a0e3b7b187c100d55fdbae7f63e92a9a84e840 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-daprd@sha256:923cd43feb1ba8114374f9decdb6360ea13f102f8664760cbbb48ea9160a61d7 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-daprd@sha256:1f8947bcefafa465a94e3334c91450a4b737829e2b5b4261864df8fcd9254e19 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-daprd@sha256:d2af6b3bd484d0020209154ce014f169bc708be1e8d2f0f029e66e60c3a239b4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-daprd@sha256:e476f558405130351c1bdf8616702feeeda5ccd598f5e4c9e40abadfc713263e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-daprd@sha256:830b74fdaa61344aa57ea8203bb30eeaf071292dadcff2e00f53f772b596dbe7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-daprd@sha256:2f515c8f79796c8d241b038ba82fee721e8aaac4024a1a2e535326b87b3cb105 |