Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.18-debian-dev, 0.12.18-debian13-dev, 0.12.18-dev

Index digest:

sha256:32e1fa89da6539961cd91faf07eb844672110d27c860dc0f9e92afa4add0796e

Manifest digest:

sha256:046b9a5e29ba7ef56acaf756127fc292990fe0c088448ee6e16b8bd50022c684

Size

60.83 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
1
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:24dc40432c5741d8d15fca39e64c57e2daeb0742a24150107f9c69aa87500331
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:900d745d91432e0da7897df7744b2d404cd6ddb714b01abe4eaecf1b4bab1b2b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:cc30bce4925d4209cd5ccef9be889590b995cdf46fc2d9ed29637595268c0205
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:43756f16dd303354b69304c9d0b4e6a6bc49b1cc59acfc163d4706a4c758e9cc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:8093f06c27d82f9a0fe6b4902bc6b466fcabd9a645df7088e51a5ed4c8f994a8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:8f685dcd1620cb5e904bfccceec80e472bfea22a8a6cdca7a26c8643a505a001
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:5d0a2cbfccbd42f990e62173bdbe53af41b882c212c1213c4f064f38f13140d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:84fdb65987f35c3240127b4fa79ee96c775275ed329bd8ef4e07b0027bc5c134
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:738be75cdc305eb462c00089772c9c7c60397ecb0da3bcd8ea7b4a6c39a41459
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:7f345e171ca4e1f9c0eafaadac78a2d3f98dbd984476784a979f58b8fcd7c75c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:5a7efe9a04bc4c6437977dd09a7d20273cdb3a83399693df513c749eb48f1c4d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:b03b2a134de1853d93be2f2860149cc151da54332ffb64b9f6ca0764924390ed
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:1c4dc8c79d273d17aa9f0e6fc0f693112c7b80ae9d9129cc2f39bb9ca80a6da4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:586244f8744d84f16eb4a1b8bd5f9f86eec3d38ac8226874a80fde8f0f20c0e1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:4924604f997804da7d7896a4eb9289982453ff25aa058f1cc89395a808a0589e