Sign inSign up
Tekton CLI

dhi.io/tkn

Tekton CLI 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.46-debian-fips-dev, 0.46-debian13-fips-dev, 0.46-fips-dev, 0.46.0-debian-fips-dev, 0.46.0-debian13-fips-dev, 0.46.0-fips-dev

Index digest:

sha256:60fc3dab64c3c1fe8f43e17793445fbd10c6fba64f5628494669295bc3535bc2

Manifest digest:

sha256:5052afa437fd1fa3b1a28f92da24e14ad6341cf21b10e0708af63d45f8d3e920

Size

59.62 MB

Last pushed

2 days ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/tkn:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/tkn:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/tkn@sha256:6f4a27297266d8b89e459196388c89eba0674d14e2950267f16a530fc51bea84
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/tkn@sha256:dcfea9ac2be840aaabd3e759127bba4185a048ecfab8360da09ded58d9c512f2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/tkn@sha256:e0388522269f71b8ab51b073545dc33d608b9e93e790c3751d09d41eb2270185
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/tkn@sha256:5d7cf049ac5bee1be30ec4f76988a69a44c92aa8da5012fca563c9ff8d8282cd
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/tkn@sha256:c2862d1fee3c7b8b04ced6526f58ec6b40ad2e7cd91027715ada859bd492c681
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/tkn@sha256:82c04b08eaa8f5b227c2709dc52ac4b270c75edddb300477333416f362c58420
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/tkn@sha256:df9a9a9a42d78f59b29f4acf43162ca439e5d2611ededa66bc7e8da6638fe77c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/tkn@sha256:be66ac23d05df4fec6a1571220e13a28d90e1f490e136eeff1dfca3b3c43011e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/tkn@sha256:af39d74b89dbf4c5ca9583ada538f64f292883fbfd567a9c7a34828d5d9ea482
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/tkn@sha256:bdff4547415c6b2da157ee7b4d9163bdcf3bc8d81415c80db8364bb962855d94
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/tkn@sha256:58d89188b2a39ecc061331c8937d0a35a15469799a4f2e071169f5bf479c775a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/tkn@sha256:a3ce57a2b6421b000e75dfeedb01cd6e66de06bcec9f7be3ca908a4031963d6a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/tkn@sha256:d9099e506d870ace07f6ed9d4e15cbc31352c12eb0d85f8bd42377fab1f20c58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/tkn@sha256:950d65d35858a5d93a3c07fa12510d7e419400ca2449439064a0816aaa2e877f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/tkn@sha256:204906d8c7d25e200f8cc5f8d6c73cf03a2c3dbbe8bcb95eb658bd842a93c3df
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/tkn@sha256:fc65546d03029241c2f98a56fe3baaddc83f65a903c5dced671759d614ef1ce6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/tkn@sha256:004c52c6d9e3a0588a220a88ba3473ce1c85c859568dbb3c601e4ab20dedba66