Sign inSign up
Virt API

dhi.io/virt-api

Virt API 1.9.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.9-debian-fips-dev, 1.9-debian13-fips-dev, 1.9-fips-dev, 1.9.0-debian-fips-dev, 1.9.0-debian13-fips-dev, 1.9.0-fips-dev

Index digest:

sha256:27a283507d5c2daef7ac8fa54f5eb396ee17ebc13bfd53114cc4b8e2729e0757

Manifest digest:

sha256:6bea25699bdd2fad4c85c08a8481823289cec7dd4fb4523e1d3939b96eecd6e9

Size

61.22 MB

Last pushed

13 hours ago

Vulnerabilities

0
2
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/virt-api:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/virt-api:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/virt-api@sha256:5e8a2849183d5ce2893045592191fd558c764a827a467aa08eb71023e3874eb6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/virt-api@sha256:972dbfb54f3c42061e9e6c09a6d7646036baa8e4b4af1f43ca0002c94c43d141
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/virt-api@sha256:c830816531ba133657cb2047cfc961a0f0d20baea9dc8c474951f5da779b2bda
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/virt-api@sha256:c522e177d0a36db9ca629433b42745ef80eec1ca4a8b7c9418084e68926d09a2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/virt-api@sha256:f8abbf25cb4f52fdef32b1e71c6a0c7ab9c1766c4f4146f9d683b9882a1eb9d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/virt-api@sha256:7b7431197c30a7100a952933c4a72ead7cc6eacb79f30ccea823d0506c6ad424
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/virt-api@sha256:52b4116ac53466fc2ecc62f36d9758f2b25afc9e3fbeb218ef539cef869760a1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/virt-api@sha256:a65f41149762e523888690708921a014b8ec8bf25ba0bc2859592f6f4778d0e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/virt-api@sha256:b4a182ee44191edc712af6a3355f6402fa6582ab951012f597dc1cc420fd48b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/virt-api@sha256:ed90d1d735ffb6189132f935d46e99fb1d7670436ee409dcfd9fb499059ffde9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/virt-api@sha256:1ca166c5ac2d71edd1bc68b6f674a748b744ead3787a17bb6142267ecc0868c8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/virt-api@sha256:64f98c4bdb82948237cd3fc0ec6c47c4d4a0a287cd43e1d7c2b00c9678b26d6d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/virt-api@sha256:c9b139d6b953dc1ea59f13ab36659f1a029a81cc0b19713f565e06f85f90fe48
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/virt-api@sha256:f962043c54999f0ce5277516d18c72c6250dcf2c3125d54a115f9843e89b4988
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/virt-api@sha256:e5b8862ac7e8cb0c065b9bfe2e6f5f801ec90a1c50683d61a76df6b655da7c77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/virt-api@sha256:dfeb2e77382d19ef41f0504776032ba1d6fdc77c2c875a75058159e8bb5a4ae7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/virt-api@sha256:6b38d3749b7aa7340e33c32ed655f04d9eb8c7956f84bfe5be92e1158f63b015