dhi.io/dapr-injector
1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips
sha256:c2d80ae6b854744495a8659fb5c66e2d0d80741523be0215500cf1aed9f8eee6
Manifest digest:sha256:15c66a6a51135ccbb9acbc6472777cd7dc08420a3de09d67901a164c9b149052
Size
22.39 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-injector:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-injector:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-injector@sha256:71c422921c10c01142f024f80f74f698423fa4046b9c076c2a4b9c3ef3cb5e21 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-injector@sha256:99ca33b31b65ba6452cf3325cfecd29f4f9ff566e1ae09cf01948119115eda1f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-injector@sha256:6de2fd3fcd49464468924656ce103ab2e6c5cee5bb6be7023a553d7338365931 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-injector@sha256:b302927e600fbb28745d1c0ca42482f290a4e4cda317396b456fe7823e4d6e96 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-injector@sha256:b9749aa04b1ca6569c395a2c789ca6e27e43cd0e1fff46ee42f1a76e75db6bc1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-injector@sha256:221ffccdbc3f23c9354e8cefbc0069eb920810a7ca7e372f436d374134c0aa69 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-injector@sha256:52a4c29229bb5f57f9816d60ec0d17849f96741b256cd52800b7ca7e1598e971 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-injector@sha256:71384fc9292d34e65c743f97a31ca15ca9a861e4305387631563f9eae79cb58f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-injector@sha256:be1e110a3de70ba91722d53fa2a97d7666eb6de858b1ad3bbe5d76eff234d12b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-injector@sha256:0cc9082741d3a4accf17c17d48356c4ff8c4dd9256cdfba300105f0e48c4c2ac |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-injector@sha256:1daf9170c1e615814fed26d1c65634a1a850f6de79179c2d916e575beaa35380 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-injector@sha256:8f614e3e8aced7bb2ab1124e79552749a61439c9d393980877a3dfa1eba9d54b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-injector@sha256:0082cf94cfd967f5dbfa373133695b7fe914bac2027cc26143e7332b278012ec |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-injector@sha256:4ca5d687cffca34814a28db4bfff9499280e4183080ccc0196e10151065a8554 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-injector@sha256:a8da1f3ece65bc25280e752d1f0f6ae560141b87aa121be18c84ce0573e124f3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-injector@sha256:af258d04bbff7aec03c26e5b57ae2a38efa761bf210b575f709939ff9ad16dc8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-injector@sha256:d7cf6d6306127811b26ad265e8ba8c9ea15ccccdcee05a24c21cf867267558ae |