Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.11, 2.11-debian, 2.11-debian13, 2.11.2, 2.11.2-debian, 2.11.2-debian13

Index digest:

sha256:55efa603548a7de53d5d81fa5feec0b96a0749abbc7ad73f7bf5363d13e2a4a2

Manifest digest:

sha256:2cbd75b6aa37fe8baf5d3f45fe64a02f246346bd88c31df90dbe4cd0f64df6ce

Size

26.39 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:b1c5ec77138c17f22cc6c266c04c9a25a96a191e5cab571323a586aa9fa5560c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:310502eb4c8d8d22e8120e0116a89107b31a1eebd94e651262c02bd16598822c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:36855ceef3bf0bd7bc5ebd1068c80a65b6150f3ab2e8f7ff62d7f73e3f9194cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:dabf24787ad7c9b83fedef99a042c48fafb765242c75d219f45ef2d8ae9579a3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:09c1f4c361e36fff3e5332800f0367619509aae60e307c58f1caadc97a027c46
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:30a874b514922322a0a05cd8f9cba66ddaf049e21e1fc54cf6a8ba3e65c0a1f7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:3829e6e03caf832759d7325182a39e8d527df1825fc55cc63e57517a5093b745
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:a4ec7b6c33b74d5bc4be88053a0d8bbfce47acb011c9f9cc8a2fd344ba4e05dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:8c8434fd412fee1e7b1098044e4e75fef14bd51986b02df1aeaf61bce34989a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:1e4913ee026c7558f789bb089e5cc9c0772b3490a9a3903843d5a20db50dd2dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:d1e2f2ea8435971a87d65b3c68a9abdfdd648c735cd030a3e391b0bdd4742d4e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:3dac3f673a8ba6378e6e5e12365d4e22e96fa23f15d0c99435219aa4252ed4a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:5401d5e8a931b27c8d13db809dad2255f3981987c7710111f80c2baf06cb2af6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:0949ab2b0692e91f167146c40a74f1a6a6be8dc20c397f52d43fc033dc8f708b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:8259782866e2183ee91ccb37a458967a7d6f70aeaa8e5a2e2471c7521fa949b2