Sign inSign up
VersityGW

dhi.io/versitygw

Versity S3 Gateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.0-debian-fips-dev, 1.8.0-debian13-fips-dev, 1.8.0-fips-dev

Index digest:

sha256:52bb931d3cb16434f01768d25b1f1a869d1b6a88fbd16737e3b0180cd06ba214

Manifest digest:

sha256:6fa666f224315774454c564715efabdced349acf5a3003070f5556ed7602f746

Size

47.76 MB

Last pushed

11 days ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/versitygw:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/versitygw:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/versitygw@sha256:42ab284ce3be2d7ebd10cbb10685511147a10783bce7098b03bf5f2e180a236f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/versitygw@sha256:a1baec85472ce87f60973dbfca0f78010e550dc868f197fc70e26b054cbb925c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/versitygw@sha256:5a1a330e39ec6c4328970a45d23d40af5b962aa550fbd8a9f71fd068654dbbd7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/versitygw@sha256:080f924561318d71086880de53c341dab9a13f4652bee04579f184d431e207f3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/versitygw@sha256:2c3b8ca146155708f284a5196c5fdab417c56c867111678ae8b006ea3a3809d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/versitygw@sha256:24fafa31a3dd619d0750bbc8cd37697ca6d9c17119049d0540412c3966932b1e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/versitygw@sha256:0b3dae709a0cf8b89cc187ade34b86f52bb3e1b54c7f747f6cdaa0d79e9a4450
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/versitygw@sha256:c19b623baee0c731fa3d568247121b9f431a1468075e418088371e9cb8473ed3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/versitygw@sha256:6fc9eca6fcd4d7cf07292718a458ad010d800978b03af554a8d9465c42fe2ad0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/versitygw@sha256:678040f8af49b1a12373787cf08fa824cf6696c2f0dac54c9ea3254e0ce80496
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/versitygw@sha256:08ef2ac79b3e3e9a4c01874a3dce45f7630176501c918102b896eac43257c831
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/versitygw@sha256:e0a6e8c4c4ee6ff4e145e1d0a00259c3b2cc814a85345b0ecf8a66c13ffda8e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/versitygw@sha256:ddd2b0833f8571f94f827590d3e94fce1e8851c6533425400dfc476a383fb976
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/versitygw@sha256:30804c020871d86e70aac644cb85e165db0b9cffa3b2717686e3012807174576
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/versitygw@sha256:27c60a9ccaae371ae2e278d4d9867a65c8819caf8f0c486bcbc4485ef7beb669
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/versitygw@sha256:9b6224031ded2adfebb43e561cdb46b91ec9f171b77fb645c402144565d65109
SPDX SBOMhttps://spdx.dev/Documentdhi.io/versitygw@sha256:da9245450a67a29cc42251b19ae51a46b2b3ee72fcac5985cd4f6eccb69c5bf0