Sign inSign up
Kustomize

dhi.io/kustomize

Kustomize 5.x (dev)

CIS
linux/amd64
debian 13
Tags:

5-debian-dev, 5-debian13-dev, 5-dev, 5.8-debian-dev, 5.8-debian13-dev, 5.8-dev, 5.8.1-debian-dev, 5.8.1-debian13-dev, 5.8.1-dev

Index digest:

sha256:044a359046079bb1e5f29c1c52e8a7bcee17f52ff29c45d7537fb20160b48c58

Manifest digest:

sha256:3fd4a3e6726a063fdf7258fbb331589314c9410febaa061e56e8b6fea2f48385

Size

49.52 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kustomize:5-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kustomize:5-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kustomize@sha256:995bc2539150dfb381315402908abd952c2f9e18d2e8fb58f74fae0f860bedea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kustomize@sha256:dc9bfa6492d7caae65a96896c4117bd70b12d015634887b17eff7a50df24d789
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kustomize@sha256:3c7627c3e08ab2e9aaffdf06502b05fd44de89c2ee6c756b6cdeea754e5eb933
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kustomize@sha256:afda52ce16881503b183eefeb0fd9ee953d39f3541e762cc2564b08de7059193
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kustomize@sha256:b4cd1e7c0e89ca280c656fed2e3f01c19f3bba8ca9f9223ebf8274a1a2c57ea4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kustomize@sha256:98d5d376a31e00ab2352efec7ca887504bc40234e1f9e61ed8baa2a39a6786ac
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kustomize@sha256:b458a28d2279abd3b6532d2288063bbec5ef5db06dd79adb76dd5f79812c156f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kustomize@sha256:bcc93e161de7656f7c97c629e7e7802db846a2e12b9e3c8273c6a7575b720b25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kustomize@sha256:b0530a0ee8ba260c352c45028481006acb827a787e41bde808a905d5ef404150
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kustomize@sha256:84e6fd7e0dc6500f8c5051b85e0d454e90b9ad202ffc022513c7f4efc5b4d31c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kustomize@sha256:73765090e790e31db0b73e2e81c610926544a173f76ff252fb995617e3412a4a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kustomize@sha256:e3bbeb4bf349739f9787264baea3ffbb8117c29ac713ba11f55e50aa26a9864e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kustomize@sha256:d0f7544bd0aa65e8f12ecbabbfdee7b4b64257a3c03ad69b727d1749ce6889f5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kustomize@sha256:e50a4e1f97874b78d34f1136bffbce390065b264be5ae98ed99e4c93964430b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kustomize@sha256:8dad09c76b3a54e01cc6676b9eba1e06c08fb1c928ae9f07f44335ada97bea75