Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.0-alpine-fips-dev, 2.0-alpine3.24-fips-dev, 2.0.2-alpine-fips-dev, 2.0.2-alpine3.24-fips-dev

Index digest:

sha256:50746af19e8a0d26b854830c783251180c7d087e7ff52d68d3a6e3e7902b88fa

Manifest digest:

sha256:fe89a52834caa23c51fd5a617b1ad1e0bbbe304b7c3d960d316fa48784d8e38a

Size

429.97 MB

Last pushed

1 day ago

Vulnerabilities

1
3
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:6c2675a5f2d0b51c5fab46d2450a82b81d781f940866c21f968a9ef37f6dc365
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:f55c9020c206775e1762bf280a52af47ed47c397ce13c99f27d2097263608737
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/openmetadata@sha256:e5aac855f0ff30ebe5183d5ef466bf033ec8a1271b9620177d5632a69a6e7427
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:7abbe6a3e1deab3d34f828cd6894809d13f1d2a7455e2f30d06b6fca0f2fb37b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/openmetadata@sha256:3a8af98f21ca15e44fe6a0eeae3677059f919a004a1d0748caa5acaefca7e540
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:f41c1593d96cd31987e7a5cf5aef1117c003d027d232e26516c1021e092ae79f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:3f4f0bd594d80e363ebddc2570e4cf6d3e2fab9575a0515a65cf8917a5023282
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:27f39560c11a59c8147e78f39933898e494493f9a46090b9abe6164364afcbd0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:f319ab4c272de26ad7903c5153fac90088dbd309d43700e84802f2a81359d4d9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:a2444df9ec34b8c23b3b5b1724bdc870eb79bb55fa3f724ff8b66d11625e3c26
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:d0864b65f88cb314021b2ee4c237cc609a6a1033c2d6eaba990c60aff1f599fb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:012241d42be409b8e1847d4ff763d0e0e9bf8c0aea0992dc3de4a8d2d63ae2ad
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:2bed8d1ced2cf7f7fb114ee7453ddcf7a6497e6292c076737d2d33229170b66d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:dc03cd6e3286a44b7c7ad166947daa3ede07f7f3e8629d49f21e1ecd1fd31006
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:6fe5fbc459593f31d93a6150da1e9dfaa6c44625ad696c1fa862da17f3daaecf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:f43ed29df1375d874623883c2f093f1a83a57d7737cc793af828a0a416a36894