dhi.io/dapr-daprd
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev
sha256:54d53deeb961b8ea16068c3332ef7914e2d2bb24c278a45f0ab68d74c36d7016
Manifest digest:sha256:442693109b6ec90741289a8a3fa3609531cda9426cef6211906426f28d562724
Size
130.24 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-daprd@sha256:eb550ef065128e11e6f85ad2849a77b3a0d62490a80b391f8769905eca652072 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-daprd@sha256:9322621e38ec712c2f833a419958e4047cf1a5b9eae14f6beb0aebfa7962a045 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-daprd@sha256:66697f880a8c2908d3bb3a4aabb56737b88aa63528b31b3e324f190b5986665f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-daprd@sha256:5312284d5a5646a2dc32d7c9996a497dbbd08ab760bb08e8ba5f2c289d2048ec |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-daprd@sha256:1ac65282f4ca030faec19d962d3ac24b59a478baf6f2649bf8e01f745290a174 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-daprd@sha256:112e3135f1e35ccbe6570bba82ccb572aed928ef77515e748c2198bdae6e4664 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-daprd@sha256:cbb9c6506e92047acdb3efbb8ff14485a75ccfeca20798bb32ac8406f74031b4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-daprd@sha256:3d269487b5c891fa2364ca96b984f612071a0ec5725a4147b20a2a64118c3c27 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-daprd@sha256:1e618539c80526d4734083490053f14123849fe22f71c665e068f92aefdb6eb8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-daprd@sha256:a8d38d84f793e7fa843b0683a1f3de162e8e68c7288c3551314c32712125d93e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-daprd@sha256:0823bfd0a33aa7f54f227a4d3f78844e6f67b3c1f5de4988749e7d0eafcbcc66 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-daprd@sha256:bca47a8dc2d5568ad45fa37edce2862437da59a83bec7c4ab6a6415f90e98958 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-daprd@sha256:2ded158d0ada4719be6ed04b211454e4e940ea1914e51047d27069ef2e27fae4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-daprd@sha256:d3f2e5f38175d31ef4ae66837638cb28fd93cc1dda87ba71325ca69e9bcd1fbb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-daprd@sha256:45ac74206b5887654ae17d29056ebadaf6464797d5c683992760a5c9bac0d2cf |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-daprd@sha256:c6feea81a7b14fd63cdd2807cad11d2d5a173cd8b9f03103dadf0b5d9226d83b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-daprd@sha256:779593b0d9272d259e1cba2c0fe8e93aadcfbec1ef00be8a52b9bec994643c69 |