dhi.io/datahub-ingestion
1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.10-debian-locked, 1.7.0.10-debian13-locked, 1.7.0.10-locked
sha256:3056190ecf116e07b4ec2c183aa896e798244d02134860a7b72829ffe4800e48
Manifest digest:sha256:39bb0f66f765960f1538fb47478ebdfedc5df0e5a553a009f763d3e5b3ed018a
Size
129.15 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-ingestion:1-debian-locked2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-ingestion:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-ingestion@sha256:7ff537ee15da6785888717a6fba46a1e1d3d7c6609303640bba1c447aeec9865 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-ingestion@sha256:fc96ec971c11afd9f56ff5323eeaede52b1f5dcc18b34df601c650f4b3c47c2d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-ingestion@sha256:14ca4fe72b3556e3003be344f2e90b33d44ae54530bf90bfce63db578a426720 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-ingestion@sha256:a025d638eee79a64c6f1f60031db132a2e1932a6067cd78b1e3e978cdccbcb6d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-ingestion@sha256:c1e075af854cfcfdf86303ad5a39ee29c94d16d0559638886a09c9955b23f0cd |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-ingestion@sha256:901ddb36c034ec19c00c0bb92d48ebc5c23f792a1e0695a449e06723bc71040c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-ingestion@sha256:06de51fe7d98d836476626f8bdf4fa524a6474d4225bdad3a56776463d7f4080 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-ingestion@sha256:ee12a66b6b37f3ce8f27780389c796ce5f2b7e1a699d8e143c810e24f25e6cff |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-ingestion@sha256:01c5c94477025c0a73d23a80f95a381e83f60c9401cf9f282e9db42309294a00 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-ingestion@sha256:cbc6fea9cb2016c22fc3354ff74d5434cac3fe587fdd1085a0bbb1f432856bdc |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-ingestion@sha256:8e96e39562149ec465545959a3d820807f530ca4f81156c59177dc88e5d7afbc |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-ingestion@sha256:4da2004e226ac90e252d4f887b9c6ef93afea73f7bb63f407cc8a2e96c3db96e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-ingestion@sha256:190a31c59ff40cdd20311da6c3ccd6b1af22e487f6652e5ac30befea8e460963 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-ingestion@sha256:51b2266d3f7ce1cfa3f786539d6c5a7188014ba0aaa4e99170c39f87670ed8e0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-ingestion@sha256:822bae653570286fef24c3bdc6801d61a70dbe812912ecb6ed1aa3b2f840023a |