Sign inSign up
K8ssandra Operator

dhi.io/k8ssandra-operator

k8ssandra-operator 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.29-debian-dev, 1.29-debian13-dev, 1.29-dev, 1.29.1-debian-dev, 1.29.1-debian13-dev, 1.29.1-dev

Index digest:

sha256:76cd3f00b725ade28401d728209d759fb5122137b1838e7ebc9cbac3cdf726d9

Manifest digest:

sha256:2d1c5a165a01ac0df76390a1dcb22fc3fd2dec6787c9f4f57b60297f27394a23

Size

49.39 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-operator:1.29-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-operator:1.29-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-operator@sha256:e736a19e9db7393061303ce064310b461de6d26eaefb1c9fb2774091ecf2f6e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-operator@sha256:7d07996f29685fe7f405aa38679a2266556b27049988df9a176af762f9619097
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-operator@sha256:1883c00ce7f53d8ff6b902fd35657286188183604ff0a268956fa29bc11bb71f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-operator@sha256:31c27111b0c27dfe10b2b2e2fe8757bc6dc5e7b085619243459c37eade5d260b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-operator@sha256:d1d52b5d26c01160db5d62a66dbc2341f814e4762adc045829ed5223c729a863
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-operator@sha256:0f058ec803628c997cc66a6ceb57bbbe69bb3821a451d999bb862d3d01098cec
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-operator@sha256:5db6cd06d8f1c0c43f162fa7dce1bcfc9424beb0d38b8c5619cf21424bd35ab1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-operator@sha256:82bc3d359fa5faa15a667c8e17f810d8bc0aee2495ec166295591be13a6f5aff
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-operator@sha256:59e44c8497e53286e0fa3bc8ae8005fd663265dba022b6b867b49d8b41f14618
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-operator@sha256:e31db8e8cdd5104df9fd40c68f1532af48fab3f1c86bee172c399a0e07f7422d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-operator@sha256:29f67331a3c8c2e56514e89a663fbf551c791f1d332cf3aefabaa9e20c2bb5bc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-operator@sha256:63f33bd890d96e4d5fade1e855ac10830ba11be92977529c21aa39c0bbb01221
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-operator@sha256:4eb32602eb21340829a3d29fcf0cbc3c1cc9566a65f9c1171580c140c1668089
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-operator@sha256:ec894a54eb41732948c17bd0018fe9373d8ba9c29308e7bfee07e8db04b0ba07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-operator@sha256:9a7cd1b06939e4dd42b10feec3c7ac9e996c58e962f9e5d0123a2ecef4c69012