dhi.io/virt-operator
1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.4-debian-fips, 1.8.4-debian13-fips, 1.8.4-fips
sha256:30c448585d8d309e59d937e97129fa6ffe6245c5179e136847cd7b3c3d53bd5c
Manifest digest:sha256:10b2653a17aca91de3880a1107e6c77ef8ebf54b14eda1f34db83bb9e0d50337
Size
25.55 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1.8-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1.8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:5ac80d0d955e6764e9b243356ab668a63b48e10727b68c1243b30ff8a07783f1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:ab7b62aba266b932528ea4623ceb4c0e3cb3a30e4a6f2e124b448e4fcdd938ea |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:e8d407a01d787a14cc4517fecda4b5f80afeb6883f21cd71f65bbd6233c35375 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:0e6410662fd1cdd13b1cbb0ca7dfa80de4cf323f68cb7b8471fe8dc9976f9adb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:941b2edf2e40990fb5848b3ffadf928ca864c97ef90d3b3daaee6d7ecc4b05d6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:12df0ee5d244ef423bef529f56b24f8411aa6f37ed7ee4c7581cef9f383e167a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:51bef1c1bfc89fc45164875d3a6b691d7cc4d00777bd4608a519b7b229806ddb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:6bf4b3f03f25bb1ab412847e2991896a3c2e375d262319a5cd588b027b3f5116 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:eabb0a608c423006946fc0d3744dd124e1aa8c951a4ed75b845f06789a9a680c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:ee9eef93da55e96142fc74eff9ee17b4c6ed2d2e29b24f578c7aac67619f151b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:38754928c3130e849728532957c5a687b65035c10096bbd9afcdcdf607c92fc0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:684b7f17a5c1634a86ba67227d3c0aa9c76782f58873f32e6fdc266a97d71815 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:3d4af27c2e7b98d5ca64d0fe49e8618a441f2b729c4ed03166c5d1230937f9b2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:8b95e5b9397424d17aa60eaf01c00419cd0a6daf288172da1cb7ed10bbe677a0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:bfbb40a939151acba0566b69b8e5096129623de734f697fd3a4d6cd717a3da73 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:4f848470f07e1969962522e53474664212ec908cc4cd70104fb8a15569ee90d9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:258bde7aedc8f1e9786c556d41db70399e3627470d3bc522e6d13d7c83674dd5 |