Sign inSign up
Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.4-debian-dev, 2.2.4-debian13-dev, 2.2.4-dev

Index digest:

sha256:980c4027e755fe13884a6965a6eafcab05ec5923fa6c95e315daac9964c3ec31

Manifest digest:

sha256:70f85f7708ccc070aab719905c3e02bdd6fc7ad4fe816e2edaaf945061a86781

Size

48.90 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:60311449bd921f84597a421cdd7fdb4157aa182c0317b068cfab5b7a4b60e5f4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:18811cdff1cad0def30c09c74d134a96f04b32bc0098d1d81da8632b7cbab546
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:032a3d2fe50c173d8319ec6b8d58538b42a592a2b9715739ccab74695d09cead
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:545e69afaacd47ec291b0750e65d689f98a2786b52dd06fb64172b1d7e552def
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:49ddb46101c32d0ff80db4fda2abe6a09976fe741cb67b7b79d62b6fa4a5db39
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:5f3669215d1586d3e86fca87ed43cf7baa18d0ea4065a105ee4d21b40d352131
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:c01f2cf220e3db999f5e995ba0493e190ff145bc2b3a2d6bdcd7811f0fadcc4f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:a1a836a0afddb9f55e78121adc20724358828bbc1f072ef8f56dfb003c242758
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:04d8f31c9e2e7036d539c73d807d0adbd78aad4881af62e04444a131c0797bef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:b40b98b4ecf862664cc39f6b17011b8b993322f97f1e5519124990a0e652473c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:6da73b18807054d4f9e075b65cb8ba4b8c5918460160224e89c522812fc5022c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:94fa722be3c22e66ffdf6fbf0f0a7f623f2d18af80d5eb6f7523396af00fbb29
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:db59cf27c603beeb0d19b7c79c40a54144411d94b56eae04e55c94f1f5bf8d46
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:2cf092dcddbff2d9fc3e2dcc13acd18c38bd988e3593578f7c20dc262dd7cc06
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:f37e6a3e0105434801b9b337b98a4caeb59df834acae067b9a397821c41b8c1e