dhi.io/k8ssandra-operator
1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.2-debian-fips-dev, 1.30.2-debian13-fips-dev, 1.30.2-fips-dev
sha256:48c718e8910a37900c85fe8ea15dcb1dc6466d6c2cc38e247f501234d5c3bc02
Manifest digest:sha256:5c5a62d2451395411fd4e056225ed4b1e32ad868af845c348b225afb2d8a71eb
Size
50.19 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k8ssandra-operator:1.30-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k8ssandra-operator:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k8ssandra-operator@sha256:240302a2bbe30ec847ad52cc25f26224fe8416b1c620144687a163149d2fd904 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k8ssandra-operator@sha256:aca1fd22d9027d11c10f6d42a1a107c8bbf154481ebafa4d1d302f05135dad33 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k8ssandra-operator@sha256:6b5c76e25f23fe54d761e59b5f09f7801c99412573c1a13bae28873db302a203 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k8ssandra-operator@sha256:7e751c00223ea2365941bc1aad11c657425038bffab044bc7da0c9c4ef5c0942 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k8ssandra-operator@sha256:93090aca390e20aded0fcdc8be515a33ff02afd5847cce6322cd9adf3ae51836 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k8ssandra-operator@sha256:342c422fa932c503f0d08b8497c4bf1661bac54337bfb82448ac40e7d3d853ea |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k8ssandra-operator@sha256:8a35b4f40b9bd33679a2096b5763b08a29ed848044bfc42ddfdeecc20b794fd3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k8ssandra-operator@sha256:363c72e2595ba11e8b32f1a59dbe2716780fc3c1de3cc73f20888eb6154716d0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k8ssandra-operator@sha256:36402f647267cca4e433055ca7f0185242978a144a6924218bf9cfa578c622db |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k8ssandra-operator@sha256:7f50ddcc61ca9fc66bf13317c65e4aee725320d97a7e7f14f3565a0cfa656a79 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k8ssandra-operator@sha256:198a6031b71e25e374a895c5be20731fe2ecd6cfa9e40f8cab88166e2427298a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k8ssandra-operator@sha256:c792421c1f9ab3b8a1046492a33b5895c8b3f97ddd80084c26f98474cb113ea1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k8ssandra-operator@sha256:c4004881a4e601ade74ddc27be754338f64f63174ce399bac6d32513650b1b13 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k8ssandra-operator@sha256:a5018a80cd5afc91c9041c5d77462d36dd76ee47d82f5a19fb9a72c9f2d94f7d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k8ssandra-operator@sha256:3dac0606795af640db8ff3a69ae49a94133e324fc22c5acf992a6692fe9b7e9d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k8ssandra-operator@sha256:abbb40ac6cf0961ea0b489de171159f56856e011c1d86a9db8a7078bd37bae34 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k8ssandra-operator@sha256:272410268d58123e42065445f7c43ad7d9ed8d2728d9a158065535eba8bafe5c |