Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev

Index digest:

sha256:518b3f590bcdfa518bc1b58aa14a24fb7b8993432253342c86676c97bdb06899

Manifest digest:

sha256:50c73a3f988606662e3887dd340f61df33fc7670201721808e6caba60e506f5f

Size

51.05 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:e67b80e2050fca36135f0fe1d60ae0e842c1b93d1947e1dce264044f40bf653d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:77c71256a0fe129b5e475f12ad5f7bb65a923f43f94d297086df476de75b12d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:475615a2c96600ced2863ed22f5ef8b70f5562c935d0e38d6be7c89f6f080669
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:9c9385873e178b5cfdaff910cfc6e867306c1df244966c5487f45712bda66dd9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:dafb5674a8d37543b37dcab149bc932ebd4bef6744ac7a942ac31eec2b4636f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:14e262559d581ea06e7244abc9140f6f630de982cbb79d1262f7b34c4aa83275
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:2c0a906574bb0a92d3985ddf3355f82d693a7a2de66bd3566870584a45484595
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:1fda50219265ff8c878df631710d95b2055442d8f31a6a747d69c272a8a99adf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:8380e6e7d690c8bac4eb8067ed77b765c8b7c79e05f46f425d830e548f83c1f5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:e122509a133d27233a25baaee5b443d58688c4fe320d3932a167489bf3bd1002
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:9b9cd8056536f7e79cca9501a7f1fb78586e0e080198c97fcf639cf93fe6ecd4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:b90efc74bde9e3005afb40a3036f0b43386a92cf4b9b63abf0c4decd425bd960
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:a5ddebc544c5b793d46b967e717a68ff58670cbeed28137e9f6473f93d2982a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:ed7663875bcaad0f2aa233f42b149080d28ba3e33317979e11f9ec0c6ce8a782
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:bb5acd8cd997ea3c845da089103d491ce71b771e5e953e79f4e6ce378784ed32