Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips

Index digest:

sha256:482e1d1146f6863b7f3859df8344c2ca1a61381a364b59de41c365721cadd769

Manifest digest:

sha256:6d54f28556c4d95c77e2b309eb744bff784609b0a800bb520c3226b57d2bef77

Size

22.69 MB

Last pushed

1 day ago

Vulnerabilities

0
2
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:109eb6a6c64600ba48feed0e73f4d7bcfbb02e675e59e0de79a87ca9abf927ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:2788651be43ea321f7b2a844132f192b738fad1bb199d94adf867e913f3dbfe3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-operator@sha256:39a173c2acdc591c11bcb23db514749c09cbeed9b0a68caab146a14d57574e52
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:25533dd96df090049da341cb37f9cb91d3268d212708a8de57a047c705f7fd39
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-operator@sha256:c920fc0afe08d5b4b69f2445dfca7780c0406abd5e36ee9b235c3a92f31b9c29
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:81e8fae27e71308aafc8e28ddd4d04474f448469cd5792adb006ddd218b7de3c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:4b433591896be8541c07dd7ae3f1087e314887bdd1692cbbcf68cab4029458d9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:94f3f384e527bcfd7c0ce7ccb25795e77bd16a62a8163c10deabb90a7851c658
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:2458cbb68c5e64c6cdf19dcd5d63a6643a84456d59a416dcec505c0cd9b71313
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:1539244fe65c9b5c266990732ad495eec97515c80f613d2a95029ef694b2af2e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:de8777c8090eec8cbe361d6f6b8a52cab530cf9c57076aab78cbe9c0231dc325
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:5f2f2d813fc6400e7e17cdcfc79ac2ee063d9253f460585360350f28fa6a810f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:52604a7d3ff55d3afe6e131472df1c5744ef49a8a83d5d69df93ed55619a1c7e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:6f7f2171a969ec0399f1f82c55b9b152d46e4e2260d3b38b2d94c35b6deadcbb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:7aec51a1172c8ec063262c3f0cb24d39e130d7e3a5ce8f875700949ba70d3e02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:80d02504fd3bb7a75ebfa423cb7cb8048f293409229c57646e830e6877b87f8c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:fc37f807694903066fb75c9e69addd0ae42f7fe2731d885c4391810f88159d3e