Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.17-debian-dev, 0.12.17-debian13-dev, 0.12.17-dev

Index digest:

sha256:cc50bbd3d8988e5ad36504d0ea903372ebe2f62234e5748adbb05cbd614152d4

Manifest digest:

sha256:52d058f89d5d832425e4be5f846c003fea08072f3d9fa739ee0ae0ddc20ba6d6

Size

60.86 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
2
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:1e75dc08ccd1c07f114e976f0548079eac80270a3fbe3445c43b8f060bc31ca2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:f0825a6c1454923f9c988a4df79f9327107baa770249f3414232c2e03a2a898c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:7138dcc87174ce983a76cb0ce1e1f0eb4b7f7c2008c689c7cbf5b6c4c73a6055
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:5ef12e55e602727179eac6036266b56483ba48584390d6368f59ee23dd7ebb31
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:b641a33214c77b588f2d22b2513584359540a4567c87b327db13489e00c9aff9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:52f4f1c3f8cdb4a195b8b494ca1f0427b2ec0d6c96b4bf369cb69b26683d463f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:7dc046ffca74d7664d71a46c077923ff2396139938b20d5d902311d8b1f41508
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:4f10b0ea46a88dc022c2926441e605dbeed699e9010fbad28343e76553d3576b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:422ba00dd1d21297989796777225af522c07b5562c3ddebf07eb710a6796b52d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:56758966c8ab53afd2b32fb0af97c37f4d1ab1e41c89d9424b44290608097935
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:5f98da7c15279c761d4895865dc55da702c53ff52aa9b5a0f9d37af13539b59a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:468b6b5a20959697f317cbee74a0672781059a483cd60bb0b811cc304064c6a8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:b5940c322382a0cda3062f4e6466746a960e3fc6a2f3697e17a3b9b7d7bde14f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:d84a6507c5866a3e279588ca35425b8078568436ef814d0f4ea7d47ea14f33ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:f70190415f78a33975de9abe64d0b1481c20dac2101b351a1792927f7ee6a0df