Sign inSign up
Jsonnet

dhi.io/go-jsonnet

Jsonnet 0.22.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.22, 0.22-debian, 0.22-debian13, 0.22.0, 0.22.0-debian, 0.22.0-debian13

Index digest:

sha256:5717d080abf4c827e59f056958361495cb66c2ac58ea31b31a6f5c9b3cb36d4e

Manifest digest:

sha256:61bb8f6d213be39afa5f20be2b10e04968829d863c1fb7a2a50e0186482c9a2c

Size

3.58 MB

Last pushed

11 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/go-jsonnet:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/go-jsonnet:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/go-jsonnet@sha256:0ed7cf2f65b2d627a38afe7f01e60fc2f68f33cf32eec4b468b15b3b913a77b6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/go-jsonnet@sha256:827b4f1461292d87d6054001fb44506c6fdc3efa0f17dcff5d5eff114634cc1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/go-jsonnet@sha256:d0944fa024f66dc79daf948dafdbd205e8e355d83f8fd75c8af5eb448206f058
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/go-jsonnet@sha256:7c8c1e6dbbe8335707dc88bf9131e77b9c5f049e27edf164bcc94c11cb4e4e93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/go-jsonnet@sha256:36ecc0b570763cb6191bd6bcd56d1e69ea09d6ceefe1a0ff0ab1fdb968bcd7fc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/go-jsonnet@sha256:266548398cf24cf409def19cd50f5d7517596daf04537425957241e445112d18
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/go-jsonnet@sha256:e657d188a762f42a8922ebfe6257b68ea71279a9b569796c32a6bd998e7f6a41
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/go-jsonnet@sha256:30f65e4f2eeb2cc3b00b1d5c63a10633e397a2f3a16f19fe5f407f8788b4d497
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/go-jsonnet@sha256:ff4dd7aadc832281894c56e388e0cd0c0fb012f2d1c7ad7c162786afc558532a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/go-jsonnet@sha256:4917c634e03eeb566493b0d409cbeac79f1ced3b1fa96de3bdcd976d7d95eb0c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/go-jsonnet@sha256:f038738cb40185b69481274dcf1e4609301cdbbc26b68d4c1d86c106d4bb2302
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/go-jsonnet@sha256:3c1d0fa0bef793bae456aed05ab5f3b323073256f15b10b2ce58ff92b72a4117
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/go-jsonnet@sha256:4656573b6f54e944909bd65b6e7cc0ee544af2dbcf89884ea889078fb81606f4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/go-jsonnet@sha256:a48de9f7ad51ab3aabe4f5c867d8d432036068dec1326c70a6c947a5ed2140a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/go-jsonnet@sha256:bc1966a451c44c52f303bc78f50184b7be98b5baff1ddc3439e5750286584cfe