Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.7-debian-fips-dev, 4.7-debian13-fips-dev, 4.7-fips-dev, 4.7.1-debian-fips-dev, 4.7.1-debian13-fips-dev, 4.7.1-fips-dev

Index digest:

sha256:a1c296d2dbc59118597c60ba564c46d133171f4de22460c783262937d25409d7

Manifest digest:

sha256:da992fc4818af3efc2a3c018272867c45d728e324a59094f6ff4f78c6c3cb10d

Size

129.05 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
4
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:6a224a9496fa38021ebc95e1324fcd631c2173bfd4df9e88f9b1b6cbc331614f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:28e0a2346a85fac244a54dd700d993379cca24e885c8c900744454ca8fba3a87
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/netbox@sha256:eb55e232dc4c71e36d2fcd6e9a29a9b7676a0d0b6b1abf2af0822601f09c8f30
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:fef465710aed97e23bb6b5ffd1d7ebaa256349f1c1d8e6e91e50f4cc2712a786
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/netbox@sha256:0eff5f77a7081d53daff840fac72817b60ad7ca5e8d30b0738963bd8b0d07d0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:5c691ae9efc12481f252c7de012d8368a493311cc03d5e07f4d50005c5eacbf8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:70f26ffb131131e3dc8d3e6b288bfe27ec33c326ad375d702abb0aac1fc6fcf2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:45e0c0ea564a2eb1e903daff3b5f95c83205ee956fb755b6a614066a1dd8566f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:17360c59e413ac1f2e155c2d86c8b73b622cf9254cff4bba8eadefd9d4b7270c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:de35c73a5cac4c970c7a1c8e582a863f554556f8b9b3b54d614bd5a24cfbb033
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:718ab9b8a9b16449d170e095fba3091a7cada8fbc73e8e3913dc42583d8e5725
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:7d50758a7ead1c15951e6217c8e5b1d0fa089b48bd25ad63aa1927929d6c4804
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:e5e8e19c758738fa28db8e7a5c1d6b4ccdd4750a4befefb3d64d4c0369d15849
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:0be8a46117f48d70af715348caa07af7d419ae4601a697cd228e1b8f3d059f1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:ad963f987ed351212a47cd2191b0fe70096d0a86d92fdc1c6f161da8f79e260b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:413c728a01d2d697b85cee343e10254d1f15ee1179e561681a22e60a3c661ce3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:9e78554826099b217af6c553f7fe54ee578cb543b96f1bfcac4f868961e44df7