Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.11-debian-fips, 2.11-debian13-fips, 2.11-fips, 2.11.2-debian-fips, 2.11.2-debian13-fips, 2.11.2-fips

Index digest:

sha256:18d986226408d6d96a55d66592ad46c12b02ccca85302cb70ce547f76840438a

Manifest digest:

sha256:ed2930051b229e41071aa73602f69c951abe80019993d1969cbdd7208983c22e

Size

28.58 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:7371fa7b999ad0ace94cd5f1ed258672cc273ae8502f51b528fb067747d4a03e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:42cd9c9e5a8d566fe0559bf3aa0e8a560dca7ba5086995e86c0c8c00264cfcdd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8s-sidecar@sha256:fed6880f832a36253647a93954c1d02bbb7646d729484bd2da440d9d64147839
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:f8c480f7e346c5cdc6a828d5a3a194bfb7a864370dace56e466285a598c43c06
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8s-sidecar@sha256:b78703571ada8cd7f93a5fbf8c1e4ff635b67a9547eff82715f4f645408d840e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:feccd5936703fc3ea52d7dfaf42e9c2c9fb59230517829184e0fdc5309913b71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:fff5d2e7b06917d6c45f51f0cbb7aef60e24cecba2f723d2f59625f84bdc3d72
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:e34078c106a09948992192ffff9a3442321d502e56ff5aa6aa4af62f637ea773
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:2a0f662105ddb66d13cdf0478b2b0755db90d8cd965a6fa82cbaa173f6a86b63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:0c143b2d69b3acbd9bb01e9d97c5aa3317471a9b814ef91f5d1b2b42f405d2bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:967f31362e67dbe9b3f9bd50a5fa207cea367bc997718d3538dc2ff7e76b5989
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:51784458909889ba98d26d2e04d2f154cc2598420bd7ef1cfd4cf9f0fcc88bce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:dd5728f1994d662e233cc3efb69834deae6fd23bfec0d5a761ca0cf546490b5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:55f62274c97990531ed99711cc593f280b09296f68efb5fe53e52054658c165a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:da33e754de363f972dbd038af2300604383c30337b6c23164fd20858ef80c475
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:643b14f9ea3cb204a45b1f9ae3ecfb324f239d432e187dc5e365104ffa2aa4e7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:f8ae35c708dea4e2e40fa66b3c76e109934cb5dd6e4ac2fbe87d61df3d57de39