Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.13-alpine-fips-dev, 1.13-alpine3.24-fips-dev, 1.13.5-alpine-fips-dev, 1.13.5-alpine3.24-fips-dev

Index digest:

sha256:dda113a9605acc2e58d8a33a6fd922eeb6a443e88792a5b3ef4e6d83e59494a5

Manifest digest:

sha256:0a0006631adaef20a8070e6bd1593bafd1a5fd58bc4b4bb2b067afa912731b90

Size

392.57 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:9c4cd2687af2bf77ce5c91683e983015a28b808293f30991abd5fb0b3d493421
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:a0917a3f8913adc973bc39d34ab9c5f79119c7f7bc8a8b5e1c8a19d14e020f2d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:b2c0b37ee328470196300494e36db7b9f034d903c29df2c310357a4233513422
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:392d6bc49f08ef6810dc0ab63fbbc12beeb9901a3b20ba2f431cb911f2b3d229
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:6989dc32bec832eb921df5aa477298c0d1b96b35c51f8bf33c03d13aba68550c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:e9fc4dec002298ad6244a96c16797928bfb8dd01d3d115b9956e7e7fd82608e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:f08ffe376e7b3595a9e61e8f889a76892da791416c0cfba6c909ca76b7282f6b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:99e6511980c429f2833859b84130dca5548ceb687ee114ce2f8159b78dba53b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:ceb421697befcb13a92dc19f92e88ad7b5e38b0b0e39d6d73418b57b452b932a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:0a6aa7e99e52d55cf979cdabaf0d3a4d5eeec448549e181bbdaa79a2902a5aa6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:58a1b34b7f5ec12421c3dc3d468bc6255c70c80a99267c862c1793ed2aa58cf6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:2d65e4dcf7d75dc7f3242e6e2a6755561fe39eefbaa905de293b25669d1b732d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:40124b4d0cd7ec23e2c3dd8e3144ed3130268162155fa7006aa8d2132c804b78
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:1dc45e175ef177c9ddf2c507c6e65beec3f5fdf18145420e386fd46b72f27794
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:e9b714d6ca92b2d29c8debaef8bd0880050ea2a278e1d3f53b68fbc9bbde9e3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:7d53e7bade2a5c57ce2105ac5f9d8551e92c3e778306b1a2dbdef751afc518f2