Sign inSign up
DataHub Ingestion

dhi.io/datahub-ingestion

DataHub Ingestion 1.6.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.6-debian-dev, 1.6-debian13-dev, 1.6-dev, 1.6.0-debian-dev, 1.6.0-debian13-dev, 1.6.0-dev, 1.6.0.2-debian-dev, 1.6.0.2-debian13-dev, 1.6.0.2-dev

Index digest:

sha256:379df1897e2889816c3a7d5dad93731bbe82336a296292f182755ef07694cccb

Manifest digest:

sha256:bff8ecb3fafcc8774fb15a4439e54e822de09434ff5d2d968824e8c53520c955

Size

228.25 MB

Last pushed

1 day ago

Vulnerabilities

0
0
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-ingestion:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-ingestion:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-ingestion@sha256:90590725341e5b87847e4c77de0320bf61450f5f956715ddea63ebc260aca80e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-ingestion@sha256:eb5fd558dde72add37a90b7b9d8730670c654ef2b6a0c23b5a4da0a04c88f291
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-ingestion@sha256:49680915c4edf19e467cddfc6ffd8bd8072b2b00fb3d1bf29d81bfdd23befc50
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-ingestion@sha256:f3ecff6b238267767793359ac8129a93d168aaeacd620be726051cd30079250d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-ingestion@sha256:3cb33b9e283b2739d1174ea76d067115015508fe0112345fd63f24e7a5d87643
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-ingestion@sha256:82791f3d9c25302beef6524ae5f8e61bf448bdaca4d82d4f8e218bbeab5b06e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-ingestion@sha256:bfacd266d9a8ac1274f7de6c888296c2563da0432fef5df5d1b99d13ca70e955
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-ingestion@sha256:c4f0098c3c9d326ff133cd1038470ea255f29d13e4c5fb326cd6695b4ce6d213
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-ingestion@sha256:067e58ab9b443b9781f7981cdbcb81237c1da7ac041337b843e0ca88e4280b22
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-ingestion@sha256:eddef0046ca73880a47c21d756d6136925ea0c2f349e0b1da441ce7d85cc3494
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-ingestion@sha256:395bb1c0747aab3aabf532eebfa0b42021728eccf3e457e82af79fd424baf6e1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-ingestion@sha256:13ddfb1bc844de14f3fe0bd13959858d14106b6b497ae4ce7246afd0beeb8fc2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-ingestion@sha256:a5437de70beae8930565704b918acdd04238d22aab4a4b29f6ea6d529377ffc7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-ingestion@sha256:51d0d614a8ce38db90ba916174e0c244185e3253eca78fc71f76d5f5aeb3f400
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-ingestion@sha256:5e78f804c20130c656892564e417a8d20b51460490f893113aa13f003b987ee1