Sign inSign up
trust-manager

dhi.io/trust-manager

Trust Manager 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.25-debian-fips-dev, 0.25-debian13-fips-dev, 0.25-fips-dev, 0.25.0-debian-fips-dev, 0.25.0-debian13-fips-dev, 0.25.0-fips-dev

Index digest:

sha256:551f1757a4f8eaf2f5df0fb4eee5fa51074a59cc4769092ea881398720e995b0

Manifest digest:

sha256:c833506d3455f6ce9c00631a1d4e2265bdf17482659b7f98b57c5a2639aedb57

Size

43.72 MB

Last pushed

7 days ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trust-manager:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trust-manager:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trust-manager@sha256:d6ed2e93b5a32af4f9f7492bc9916f1f35cd7156ccd46aafd12c9b35f4a35112
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trust-manager@sha256:24f84e0ace8fb6a1c64a9a0547c4a6a96348695892d5e01c2f65e017eff64faa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/trust-manager@sha256:49251cbd17c36b0476b6b662545703187a4aca709c50ab817a05b5dd2affe491
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trust-manager@sha256:8021165f39df1a78b0e2b33acd9bda37af20f405f8d7cf39b7ae534da1968d9a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/trust-manager@sha256:c1956bccedeaa26003b098f0070f664af707a87fd5f8e2a64156e9a28d4eac58
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trust-manager@sha256:e18b45f2bc0b8e00b714efcdc9b6a6bc47df0a871ce4a1471fae4e26e107d87a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trust-manager@sha256:5b107ec3524942fddc8af506dbe82b33834431b9c87b1f5c98a3cbc011cbaddd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trust-manager@sha256:3c582e26d4dac7d1b9c91638b9f39acdab924ed6df432e272f27e23bff1d7b3b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trust-manager@sha256:31acee4451e8346e3a9b006af06fdfdf5b5d76fe4ad2cf00e2d0164ec1d5d425
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trust-manager@sha256:6229f1772b09345229ad4d9c9ba4e44bc1efe1da9cfe5754d3bd038a6d24d013
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trust-manager@sha256:781bfa9693d41cb24c508f6058490c04eb6761a1423eadd8b73c39876d51c8ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trust-manager@sha256:b9a9bd2d632ccca4ba16cd391e35c79beb710145ae497357b911bf47940cea11
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trust-manager@sha256:230973b95eb41e652432ef4204a89749ec02fdb21b818820b8e456ba43bf1269
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trust-manager@sha256:39796fe7d5862129fb06b2383fa5eda43cdeeed145afd582acd6dd26c4054e79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trust-manager@sha256:a44184fba15af55417da3d378808a68a075419576acd181ba700fd507e5418d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trust-manager@sha256:f17fa6f4e818a907fd1c85159716a63ef54cef0dcd87c923841de12e09aa7af3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trust-manager@sha256:bd75834bb0518e7503f414929d4cfe7c068aa10b11a905368ab5d3d67689c03c