dhi.io/netbox
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.1-debian-fips-dev, 4.7.1-debian13-fips-dev, 4.7.1-fips-dev
sha256:a1c296d2dbc59118597c60ba564c46d133171f4de22460c783262937d25409d7
Manifest digest:sha256:da992fc4818af3efc2a3c018272867c45d728e324a59094f6ff4f78c6c3cb10d
Size
129.05 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/netbox:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/netbox:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/netbox@sha256:6a224a9496fa38021ebc95e1324fcd631c2173bfd4df9e88f9b1b6cbc331614f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/netbox@sha256:28e0a2346a85fac244a54dd700d993379cca24e885c8c900744454ca8fba3a87 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/netbox@sha256:eb55e232dc4c71e36d2fcd6e9a29a9b7676a0d0b6b1abf2af0822601f09c8f30 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/netbox@sha256:fef465710aed97e23bb6b5ffd1d7ebaa256349f1c1d8e6e91e50f4cc2712a786 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/netbox@sha256:0eff5f77a7081d53daff840fac72817b60ad7ca5e8d30b0738963bd8b0d07d0e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/netbox@sha256:5c691ae9efc12481f252c7de012d8368a493311cc03d5e07f4d50005c5eacbf8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/netbox@sha256:70f26ffb131131e3dc8d3e6b288bfe27ec33c326ad375d702abb0aac1fc6fcf2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/netbox@sha256:45e0c0ea564a2eb1e903daff3b5f95c83205ee956fb755b6a614066a1dd8566f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/netbox@sha256:17360c59e413ac1f2e155c2d86c8b73b622cf9254cff4bba8eadefd9d4b7270c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/netbox@sha256:de35c73a5cac4c970c7a1c8e582a863f554556f8b9b3b54d614bd5a24cfbb033 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/netbox@sha256:718ab9b8a9b16449d170e095fba3091a7cada8fbc73e8e3913dc42583d8e5725 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/netbox@sha256:7d50758a7ead1c15951e6217c8e5b1d0fa089b48bd25ad63aa1927929d6c4804 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/netbox@sha256:e5e8e19c758738fa28db8e7a5c1d6b4ccdd4750a4befefb3d64d4c0369d15849 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/netbox@sha256:0be8a46117f48d70af715348caa07af7d419ae4601a697cd228e1b8f3d059f1c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/netbox@sha256:ad963f987ed351212a47cd2191b0fe70096d0a86d92fdc1c6f161da8f79e260b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/netbox@sha256:413c728a01d2d697b85cee343e10254d1f15ee1179e561681a22e60a3c661ce3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/netbox@sha256:9e78554826099b217af6c553f7fe54ee578cb543b96f1bfcac4f868961e44df7 |