Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.0-debian-dev, 2.0-debian13-dev, 2.0-dev, 2.0.2-debian-dev, 2.0.2-debian13-dev, 2.0.2-dev

Index digest:

sha256:8b54a3f7596a452ef4c1aa68ab6c93ba4ffcd331f11f468d1f80fa7cd25fffa1

Manifest digest:

sha256:7f61f24bbdee3cc28154080524925795d11e502565544e6c21ec4e667196b792

Size

437.24 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:87528fc180a9b48a705c49fe3af9d628e9e33a06a81444181f04585b200f4115
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:f668d127a67cc82f6033a37562579c18c861c44cbb439c86cf183a26952aad81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:ec78b6cbb41cb1f7593558d56973a881293f4c0018f8d91db0e2cee24545774c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:5f894c799d448d99d6f869c1c9fb3483d0aa8f3baec57b3de1e9d86f43c960b1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openmetadata@sha256:d2b385fcf06c95b28d35ec4d8a06a77a8c40f358aa47c9c276b3173c954ebb3e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:105f5e42e6bd0824cdc1a5ec5d8206fa45c16e3225b915f495cfb4a6c857fc5f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:60871be5cd6c06c2aeb4f697d8137852a1d14af5a5973c2f1b85f3792dc95a5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:88e6138c3a381e6b4d8c70338398ef85ebc7ae1800f8d384fa8dd6dc8b7a4a9e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:de08433824c20a22b25713589a997aa4f9bcad4b288f89fad0a26802ecce4003
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:386ce91874a5e091fe61132db958dbec51767579688d551105fbc58c6dbbb254
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:fa8f3ca67ca67bb46951c609e490674d7a1f8e92b80908dc5e2c7218d9d52b22
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:288f4fec74f1192852512967fc30e183862659ceb5ea7bb718cc852449422dee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:774e37fd3c645d3f49a5fc12d8ae10a4eefb850a329a6cdf12a4076794038ac3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:f68f56d56cf20f741bdad96161e78c6a772bb8e3530ffdb7e9b998b60d71063c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:3f79fa755e60c0db6f478db6a28e3f7412f0d8a76ae74508b70b5c272170db2a