Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (compat, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-compat-fips, 3-debian-compat-fips, 3-debian13-compat-fips, 3-python3.13-compat-fips, 3-python3.13-debian-compat-fips, 3-python3.13-debian13-compat-fips, 3.3-compat-fips, 3.3-debian-compat-fips, 3.3-debian13-compat-fips, 3.3-python3.13-compat-fips, 3.3-python3.13-debian-compat-fips, 3.3-python3.13-debian13-compat-fips, 3.3.1-compat-fips, 3.3.1-debian-compat-fips, 3.3.1-debian13-compat-fips, 3.3.1-python3.13-compat-fips, 3.3.1-python3.13-debian-compat-fips, 3.3.1-python3.13-debian13-compat-fips

Index digest:

sha256:b179495d9132dbf13a7720239b7d74a467321eda38506569407045dc057bcc20

Manifest digest:

sha256:f3822fb333258a032620e37dcb344c52b56a4bf644df5df2b887616f3e1ee663

Size

381.28 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-compat-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-compat-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:04e4e99567b6d8aeb0c4fd8b813280480cea41b1bac8a1b4ed53bb7188379229
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:dffb75988ae5463affe5ead0554083dcd92a55ce17acc6361f7e55d6ff6e4ed4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:c112b2e48b25d8f6fd28131f87205223823ab7c05ea156cfd696f60407a2fb4f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:acca060140d6f2f60e9ba08c7f5133c67f60805e9dfbef03cccd460fb801913a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:c5c6b613cc128e0658c013903caeb37f9c2c437d21dacccef6c0cb692a8c2aaf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:3714b6c7ae6971b326d13565ebda02b95de4f9cbb9e2cbcaeb34928a63f1bebc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:262b0becf6ec9c6d97d21c4bec5b2ca7d4ed78c4408fa1b4ce0fa650ff976881
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:090a018cefc93431b34ef3cca49a3412ef2d1549b84d238838ae76ccb98bed36
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:61c45954decccd5b9b57e1562388cf139e0588bdc133e9f19060dcb2bcbe3bde
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:a37cd2864c3e51a2f0d95135545862d20b7216faed920cc5d450c0121accf0c9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:1477e66eb821573c5dc3f68c965c79bf866e0c085bec86559073d867491f0f4c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:e6944b214f9acb46b3d024c4462f9b9d9d98cb7de9997045257592387ca3941d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:8db7dc2e0ffb80e77a83b2ff132775b2930d1e97fab30c708c0be0c57d1b209d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:d680792a89062045c217d280115ffa10fb72a9bfa4b9a0204a6b9d3547675196
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:2fa050684148baf5cfc28b5bd8e60992cc1cca96418190452f38129d2e774d58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:1d254a82070a0512385c8fde611071c68438bc8f51053b0689264585e9ab3883
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:ee9bc0d61afd37ebb40803303d4ecc6de1e03adcdb31d328a25aafeb13682a19