dhi.io/virt-operator
1.6-debian-fips-dev, 1.6-debian13-fips-dev, 1.6-fips-dev, 1.6.6-debian-fips-dev, 1.6.6-debian13-fips-dev, 1.6.6-fips-dev
sha256:547dcc7434aa937e9c282b7ff9965bef70da8970dcca677bf630a0b684f562ce
Manifest digest:sha256:cc9ec52b630dcb8b19bc02b112fe06980f0e35186201d0e0d761d2997755b5a8
Size
55.96 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1.6-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1.6-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:7698e9b6d6cb43fea7449c090b85877bf45babb1196dad32f43de73bc4051dcd |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:c64225bf8afba293ac773acd521edf7619a3f7de5fd7af96a0ed9189667c2c8d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:c8c8aad763cf7c065e785fe9b9dd5d9bbcda2f1e3b646086335d8bf17bad607b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:6d837bd7d7b57d03a9fae13d68bc9cfed0c5357bba8506fb67df385140c4ef81 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:2236da566aa72a64535bbae5134a9535997a015428594c57227a03f4dd8b9f0e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:e4f9602e2a84159fbfc57576fffa636ee591507b01dd821c9cbcb59a0b92199e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:fc0c1d937462dafbf883df9e1863006db46faa63cb9714069d9159be05e713b7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:cec66b0460506f2ade11a88478f5a80584abc55644cf3392e953d47634079877 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:17f2f70a220d8e0996c8d92b25213859c3e6ee453342938e247f46de2bc048e0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:856d030bc4f16b971823154df83aa82d74f19c4b98c6c39c52add18dc65d7aca |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:26426c803df67323e24453d8cf95521418b86588791b93f256c8aa87bf15bef0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:f34e4cf86bee8600bd488cf6686351b60ff63824122df0fab3136d1d78e309e8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:1d026aa5d833fa6e7f6e3e0f1f7b36eed7beeba789dbfb833ff2c241c4c43037 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:c2ad391d91941f3d5489d69c16ac519f39071f1994c3db145509d503b5dc3429 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:818433a8209cd3a72bb4ff29636ed8d63f160987b7414f9e2a0df08c9c7871ad |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:05ec1dcbbeb938ce4b44a22e34ae8c5a111cd7a293a49c4e926c05f7c108cfd4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:9cfed6c1495ca9c888534c787f3db6225b64eabd2d7e8bbbc0d6df1ab2b0e212 |