Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:8c0dd313f8b9ac8aea1b60e4d6cd707a3616c07b9f7bb440c9aa0d4f52f31c3b

Manifest digest:

sha256:af84525e0d8e219f528ec7edc7b0feefa8480397bcae8d7d5f102f73d5aa3b4f

Size

51.08 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:6bc6dfeb992c54579f72533b3c3b4373690a22ffe67d48a05afcbebad21ea73a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:95d3027a3317d1fae1d2512be5b2aa62fa8279b56535ff917a1a273730de0f0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:00edd224757ea9643d5373d49aa7bc44cdaa76dac6137b7d541d66fe7aad9f15
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:96484f21924a4bbef4f4c80b64fee29efcb45e9b4212d0e59afe288643755cad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:22b210555dd6633daf87e53cdc93d9415c96a99cb9d7405a0754a65d39036809
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:9feb43c5b2fbbb6e5809c00a38c63a2c77947526de2617d98f0fc4a41d08aa7b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:2be0cf4c1c1b56fa90a8ec0c27e88f377650a9547e5521f784c940817229166b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:ab25c455b98527e50a5a14fb0b58f159caa636e334640c174e4ff70651d0ccdf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:e52f7f8f42213d33b8c9590ec2378350a73c26c14d74ac533963c4dc2be54494
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:aa0013d6dc285bac1d5313d44cf9c1500dbb065b059cce93a398e234e0fde6f6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:1e784bd888f3012c14c50a9534a0972eb8318d4cde9e3998af26d22fc98152c2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:ba2c944ee435fe3b68057291e9462b3ed7e9c81d9f46af140a9afc60d2e44872
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:418190ec923fb69a79519c87c6ad9e7321c0236801e1a66476c59f646ce81696
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:fcc3bd2bb5f0ba5e5c7f7d753a25c032050200ed5090b333eb4ab583bf9c6801
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:476395c225b3bb1f9574365a855c5acbd914c1dff8af82897c64e33b2f6d9d39