Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.18-debian-dev, 0.12.18-debian13-dev, 0.12.18-dev

Index digest:

sha256:f1100f071e8084c1df097a13dca90027675a18c6822beb4004165c09762e4383

Manifest digest:

sha256:0c7f526c06f2e2383f1caea1d19aa69b63f1c438f674d55221361f59042b0eb5

Size

60.83 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:6edbb8cad46bd6fcdf166de1de35caf7fde213f86ebca9d289153e62a17586bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:bddd6b028c17e3250fa712aaf8788f9bdfa2b859234c3187f31657da9614abf9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:b682f78b4a6b78a61dcf063600dfa131a08728dff2aff7672bb92e5497587067
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:6dc645abffd123713b82d753566215e2fb0c4edcce4120d1d8cf87823bd6fdf0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:174e21e19d81b45c93f727d78b07a2bac1fa77ea68967e4f9f22d7fd67609928
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:770bc13d19f450bed9e53e081cc8e819149b3d3dc7d228a862a6585296252863
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:9030e129950883b8f94b9600542cf4e09b4c0ae7c42e3cd4d6c0c164e3a6a822
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:14e4a303fac2f42dccd7de2cbbae9c8df0be65973961150d0c3c847c0294ecf0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:f5fdb28997213800fd08d731ce4e4e33e0372a23b13294bd80939a1fd8f01a5c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:dcfbb85a48c14243623573be9200f92c46544c31863521d7db87f3435f0b92cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:ecd0549dfc50d42dd65bc166f05c93532ca1823d15cff04bbd391e56e75317ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:f2e184f2a1a4845b4347bb2ca28f8e4d88a396cc890443d2af124fffeafcba2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:092ccf0c29390fc634032f40daf99e70e2fadbd2725c7958be43f2fbb5cb2450
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:866e1c84738b2d5986eb9ccab5ae421f0a74d45466f73eda50179dec1e49c349
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:d830f8fdf3daa826d28533212e0a9e9ecb57d11857f0e52d498318f5a679776d