dhi.io/virt-api
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.0-debian-fips-dev, 1.9.0-debian13-fips-dev, 1.9.0-fips-dev
sha256:daa9a44609db5d73e6a0b065a91d1d8c881a46d30fba789358887ef5f837ccd5
Manifest digest:sha256:2349cd7ac9bea6380acddf852cb701e3643ee0e3ee626b1a1a408734cdae6055
Size
61.22 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-api:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-api:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-api@sha256:4ba57c25f90d7149426ac87faa888c7358d94d361996c08552d1ec9006e1a8c9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-api@sha256:de8a655f20ebc7b7562b2f364eff96055819489c0e7f55c785bdb5b25d72467f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-api@sha256:759283444d4d8de3623126cd3895ea9128ec1201a47b7735511bb216c4263157 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-api@sha256:8c25d5f86a95d40bc6a39bdada7201e980a319c5f3dbc3f438f2a8eb3be7ab30 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-api@sha256:c2dcbd2e19b4e1cd57c0c4646800736efb271b4a2cd86ccf3fd9ae260420f708 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-api@sha256:1b0cb796b807e3efa420f6dd33e520ced36bc3fc9eebbeb701de66dd2bf64f5e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-api@sha256:a7c4a9c644b6a492c04e9fa08128d852fcba9f2fefc2ee615e8ca16dd2b89b3c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-api@sha256:22aaa99b55bdb802e1ae6edc459d6023bd7b77693007b381836ef4b4915337b6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-api@sha256:38df7486858bdfbf31f218b5148d0d2a509e8b2b45a2c2a1ca50f77538997f25 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-api@sha256:c478808a23c944a6af46993c7ab030739695017ae47954d1b4d1c487a9c98a26 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-api@sha256:a9ca734da184eec1c245790eb0837ed6a65530c149c31dbc3de077b698a53870 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-api@sha256:47a6a8dd5770a0c03c183c97bf6e1030bb4e4d6d4f5da078f02155fc510cf946 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-api@sha256:0c47671a13d17f5ff4d64c84c47d54d6d72dba21ec0b1b204a05bdf3ffd7f17f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-api@sha256:d2244b6c1c2b9c413c18a0f884610e172bb46ec84746f75e303c1c6cee548170 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-api@sha256:bb74d3f72073da299c945d5dc978d57a0b60d439524d286f65501546b43be756 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-api@sha256:af5c260011c8b6303ddc7d99f6e05348844008e1c8ba5725070d7e8dc8fdfec4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-api@sha256:47898cbb7e73690dd4656af472303727ab04f0c9358f7a24d70e0988d7c0e150 |