Sign inSign up
Knative Serving Webhook

dhi.io/knative-webhook

Knative Serving Webhook 1.22.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.22-alpine-fips, 1.22-alpine3.24-fips, 1.22.1-alpine-fips, 1.22.1-alpine3.24-fips

Index digest:

sha256:3c39562dc2bfc93d283c44e440187efccd3756926844e678718e29fd76e3a0af

Manifest digest:

sha256:d1f53d5a77b9ab2ebabd80d3dc5556398dfc7de33d0eda17564980b0c408407c

Size

17.87 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Nov 2026

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/knative-webhook:1.22-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/knative-webhook:1.22-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/knative-webhook@sha256:c843f6364c7f19d388a6de630ce34c78751202233890d95371bb9d0711444c85
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/knative-webhook@sha256:a19e489e6bd2d67bd5401fa656c0901beed52a1fcfd22821586fc4b252a11a22
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/knative-webhook@sha256:784c4b6c89bf63db265148c16492c7f38b254e6aed6aedcd489408102fc48bdb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/knative-webhook@sha256:47fa796acdc788b7188a056e17e8d6ce2850b6a2462fcdc8bbf318d8cb1dc23a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/knative-webhook@sha256:7812dad28f45889cb265c9d6823c8f7a239bc3558dc1d4c46e6bd422abf7f80b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/knative-webhook@sha256:95fe17f74393f97e57ecddbc44f9952e85c68ec3be1b005a0dd73758c0832f0b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/knative-webhook@sha256:03ce174ccf07e68029b8219c3443888478ec7e4c3946161bf7e87c1ba5a4f378
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/knative-webhook@sha256:d01c98b72e7fe11b8c4c5046cb707c422cc223c952e28389c9a855ea3c7fefb4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/knative-webhook@sha256:882df09c460c315e44e962ee9ebf117cc0a9506d6c924f331e060f81a538755c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/knative-webhook@sha256:9514841e7b7224088a47d2a7e5d0fc54c2beac7712b725466a3135bc3088ae9c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/knative-webhook@sha256:488ea6df2cc4dc8e8fbafddc535d686f35fe195ff1ce169dcc5f9d942e8bb0a0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/knative-webhook@sha256:b4e25656f65283cb02f3ef90517a656fdb627ef2a2b932a82c11cb5164336e10
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/knative-webhook@sha256:fa4adb2c9ea81f7596255b6f3d0ad75f6273fde8dbb8e289eae159e8a012db5f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/knative-webhook@sha256:68c99a4008a98fa4be12271d4563ac059ec0aa472f3faccd112ec323b58f41bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/knative-webhook@sha256:a1a0a0c0fd081ea1af60bc59656cdf76a227680082b7cbcce50282b255df04b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/knative-webhook@sha256:3b69685f85047b628733ce452c754e199b403739c70bf6469ec1769621e6ef46