Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.12.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.12-alpine-fips, 1.12-alpine3.24-fips, 1.12.14-alpine-fips, 1.12.14-alpine3.24-fips

Index digest:

sha256:3a4f2d2f6676c2b71f76eea8bea0e1051a5f09fbe980e0618c7abb1020dcc8b0

Manifest digest:

sha256:1b406a4ceee3e9e712fab3f14e384827cd5ec8578905432de10422540dd58495

Size

373.81 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1.12-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1.12-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:35f41b9a5742ab4aafefda485c5f25ed78319949b9016ddff8f57fffe321efe0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:89cf8047465c04d18b6e01806e261620707be150b240aca737b76ec35559cbb8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:78fd28c037646be5208db3371311a76f1ae0faa6d56cf362a23b62dacd774d98
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:9101fe3eccc761e69e60e81e0907d46e04d1464f07e4f885db83d7075b63ac77
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:351e0249d994df72cc5f5a49e54cfa54a989ed1e676c89d31518e7cdae71ff12
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:59751cc02a25e38ac43221ecdd72b2602559c1044c9851436c3b397026b8f438
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:0ed1113f39563b3cb7632dcf4d7879a9ef1ba42d21100fbf7566c82b73029431
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:0438e2eb25ba7e621ff2e427e53318bae99f30619aaa099724c184056f86ff66
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:59db7ffe25bf88976c673e4db368b0329cb9834f9ee04668ede94d8d07361acf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:297b63e7fa126c3a44a2786dbde943dc017895e9a1ac078fbb53d8d0bd799914
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:4f6cc3137edf278a54438c033af22c21ee36d1837e01f1be953b9ff6baa17f2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:78cd8e6c117f5fde92b27e4253def05f07c45301bb80d8962884b921cbcdf98a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:baa9f4927d3fbad7c1791250e43e785ab4c62c446b61292c58751bb822466861
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:ddabb98e91acabbf26db33f3010f200ac59c9986934e4753e86a991deb4d6d7d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:486a5a32d26b3dc4358576797073cc69aecc40dc33dbc732b38b97c340e2fbfe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:c75fc13c0187119d33c8d28a172d1b11f4d009c69699b6904a5a2ff2adfd9297