Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:cbfdff0a9491be4815e6a739f6f4e0df35f9e6e92a7c421678a9f289a5b4dcad

Manifest digest:

sha256:c8f4c816ba3f45719ef7c169b1077bdf3489a236aae8da6690495629bd9b9196

Size

704.14 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:9153b7aea810d0a48d0f51667b731ca7b4a50aaa03c6605a2e878ea9c32c03d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:948c78617305efe5bebf4d37f8e1d9a63ec4b439057b4dfbcf5fdece6d21e0a5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:c53b80451de0001a39a67dbfe8a066c30e455fff53a303b0fb3cf08958ed26e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:d6eeb8730737ddc5ec442f7633a4852d765031727eaf448d91921a78def9ebe3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:8f34d64f068c6e6cf4c9ee7b2a1f8653a985b0fb258bf9a6567f1122f69526e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:8319d17ecbcde1af2138aeacab47c89f120f0c827f62006f0dd0ca893c396660
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:0692988b05aac83c7a9cf15c52518fa0776bc574412015682db22151cd8669ef
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:1b2bf416245b37065958ce2c41107abdbbb77f8ae1892b873636156c18995e48
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:5f171d687da34995a2b5e89eb8c06f4062f77e06794a3c783504dc9b5aa51f60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:35b37b2bd5fa74a9b0f1c5ca95e8f5536bbfce5aeb6b9161df0d218ebbca11d6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:4831706875b6152e776c6f3d50011515985c4747370b31c2defecb76fd224131
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:303c336561929e728d5cec6d33500ca62ea593ba3043f28a67a5a24e3703e170
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:e5a2d1fed80dd2d303b8e1b6ee7f9945c40020598cf5eea8e0ffaa893b309362
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:2a7c99ba7930fc2da55149c5c428a8696be30aa6d350b6ab4591899b34c21082
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:1b654158c72ce468819a3378c4ef70d9dab24f580fbb2ceb13ae1993cc8040d9