dhi.io/datahub-ingestion
1-debian-dev, 1-debian13-dev, 1-dev, 1.6-debian-dev, 1.6-debian13-dev, 1.6-dev, 1.6.0-debian-dev, 1.6.0-debian13-dev, 1.6.0-dev, 1.6.0.2-debian-dev, 1.6.0.2-debian13-dev, 1.6.0.2-dev
sha256:379df1897e2889816c3a7d5dad93731bbe82336a296292f182755ef07694cccb
Manifest digest:sha256:bff8ecb3fafcc8774fb15a4439e54e822de09434ff5d2d968824e8c53520c955
Size
228.25 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-ingestion:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-ingestion:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-ingestion@sha256:90590725341e5b87847e4c77de0320bf61450f5f956715ddea63ebc260aca80e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-ingestion@sha256:eb5fd558dde72add37a90b7b9d8730670c654ef2b6a0c23b5a4da0a04c88f291 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-ingestion@sha256:49680915c4edf19e467cddfc6ffd8bd8072b2b00fb3d1bf29d81bfdd23befc50 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-ingestion@sha256:f3ecff6b238267767793359ac8129a93d168aaeacd620be726051cd30079250d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-ingestion@sha256:3cb33b9e283b2739d1174ea76d067115015508fe0112345fd63f24e7a5d87643 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-ingestion@sha256:82791f3d9c25302beef6524ae5f8e61bf448bdaca4d82d4f8e218bbeab5b06e3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-ingestion@sha256:bfacd266d9a8ac1274f7de6c888296c2563da0432fef5df5d1b99d13ca70e955 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-ingestion@sha256:c4f0098c3c9d326ff133cd1038470ea255f29d13e4c5fb326cd6695b4ce6d213 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-ingestion@sha256:067e58ab9b443b9781f7981cdbcb81237c1da7ac041337b843e0ca88e4280b22 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-ingestion@sha256:eddef0046ca73880a47c21d756d6136925ea0c2f349e0b1da441ce7d85cc3494 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-ingestion@sha256:395bb1c0747aab3aabf532eebfa0b42021728eccf3e457e82af79fd424baf6e1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-ingestion@sha256:13ddfb1bc844de14f3fe0bd13959858d14106b6b497ae4ce7246afd0beeb8fc2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-ingestion@sha256:a5437de70beae8930565704b918acdd04238d22aab4a4b29f6ea6d529377ffc7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-ingestion@sha256:51d0d614a8ce38db90ba916174e0c244185e3253eca78fc71f76d5f5aeb3f400 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-ingestion@sha256:5e78f804c20130c656892564e417a8d20b51460490f893113aa13f003b987ee1 |