Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:d9bd87f9d78b7d0e5c633f913d3411af6c7f14b23389618aef926ef65e2416dd

Manifest digest:

sha256:3a5719a18e4124005f575a5076edf40e55a3909ba37c6bafdb80ce9f5569c4a2

Size

130.25 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:c7b2f9a296e213ad59188c751e89005110893e89b04f4ed38abe9620752c07c0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:4d9755fa43647ffcef9b3471fdcd553fc6276c858bece8759fefec4f46d1b6e8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:78d46842891a31af0bdf520d511b1eb4c0a06e5ff39db87b4bf46047774e2d17
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:6f83b63e600146dd9b9c06d716911a8609b24f33094ee82ca476be1c58c746d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:ebb5dbf76d84d175fe6a97d1951900dd22bdd1b0e709cce69d715245e0ef1285
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:51edbba7a1e21340082b63fbb194b1916bc321f0cc6fda820f5cfcb4164da79e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:4bb90affa429e43b2925fcd7b4c5f5bb540b087048377881f3b85d8839eb2df8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:75fd815e0be67141ebca65a989a6ba0264eeb950cb7082c00783230f800abbe0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:60d11d877ea17c8526d98c927f08de5bb6d01034f2bd2534853c4011ff057926
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:0bca9b2ebbfeed9bba9910198a26a4f28a55f105381ea683c32dbdf2ce9147bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:ca9fe051f98c326be36cf84737a0e3b7b187c100d55fdbae7f63e92a9a84e840
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:923cd43feb1ba8114374f9decdb6360ea13f102f8664760cbbb48ea9160a61d7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:1f8947bcefafa465a94e3334c91450a4b737829e2b5b4261864df8fcd9254e19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:d2af6b3bd484d0020209154ce014f169bc708be1e8d2f0f029e66e60c3a239b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:e476f558405130351c1bdf8616702feeeda5ccd598f5e4c9e40abadfc713263e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:830b74fdaa61344aa57ea8203bb30eeaf071292dadcff2e00f53f772b596dbe7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:2f515c8f79796c8d241b038ba82fee721e8aaac4024a1a2e535326b87b3cb105