dhi.io/open-cluster-management-registration
1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.1-debian-fips, 1.3.1-debian13-fips, 1.3.1-fips
sha256:fe997484a2fed769652afc0cdcaae6f72c512acfc6305b9b28d746c184643277
Manifest digest:sha256:f4fd1d4798831063d590eef0864acf8c1e7738b43ec16b3f741f0a00b7e5e8ee
Size
32.55 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/open-cluster-management-registration:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/open-cluster-management-registration:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/open-cluster-management-registration@sha256:fdcfc4d63035851c93e95561f357815a108f087723a8ad2786d0a25d7a596590 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/open-cluster-management-registration@sha256:fe7b2322ce480a1f3132362ecd074d9c8c349c64ecf0d19559ad59bbd87f8af7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/open-cluster-management-registration@sha256:3be33da79b6809ac3585d26fd5599d02f8bbe2f2f762c9c151051c1e7c36a4d5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/open-cluster-management-registration@sha256:eb140fb08d1b227c768da5f051e62da1bca86f227e61fc87f6afeb32d98637ae |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/open-cluster-management-registration@sha256:e8713d233fb7a09a0b56330d85d10178b20928854c60736dd4d867965eda8ede |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/open-cluster-management-registration@sha256:2e297987a9e546e0e90ce52beea13de9af919641137ed2c55cb07596a7eb1c4f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/open-cluster-management-registration@sha256:9d70ff1c479328240071a2e54b952d0a2a6da33a0bc69a7b646b692767eb3b56 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/open-cluster-management-registration@sha256:f0ad520d450edbf2ae519077c91c7ac8e7913e8a6f9f3c91d8bf97b17267fb2d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/open-cluster-management-registration@sha256:cd032aa39df9379eedf142f0d418bddff424d48ff12dcc55cb9fee750bc985cd |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/open-cluster-management-registration@sha256:3d848caccf0dde51296ec520bba7426d4b3084941413cee75f5484c36bcef04f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/open-cluster-management-registration@sha256:8091990cb7ce7fe5112d75b949ded2c4f25739a669ac76f3917b3b35a8b4b229 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/open-cluster-management-registration@sha256:7c42f9ab66ff94e6a5471e6669a4313aa8688871f03fad9ce03556b394e7416f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/open-cluster-management-registration@sha256:0cd4ec2de46ac2600b9f7c5fce9e358018b2766a6a453b5f293fad1d9a76a5f3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/open-cluster-management-registration@sha256:32424e2902ac6bd9638d4fbb098c1e6f96879bee1a37a2efd9fca77ffb7a9056 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/open-cluster-management-registration@sha256:9bc09fb40a40f858392447f22465901502f49dac5cda9860a0b55c500e3785cc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/open-cluster-management-registration@sha256:ce26c54046422a9b490f306e137b833318187a9e460dedb7a538437fce8714e8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/open-cluster-management-registration@sha256:03f35609a6501bcb0712117c87e43ead60499c32c138bca143be92a2909cb9a5 |