Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3-python3.13-debian-fips, 3-python3.13-debian13-fips, 3-python3.13-fips, 3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3-python3.13-debian-fips, 3.3-python3.13-debian13-fips, 3.3-python3.13-fips, 3.3.1-debian-fips, 3.3.1-debian13-fips, 3.3.1-fips, 3.3.1-python3.13-debian-fips, 3.3.1-python3.13-debian13-fips, 3.3.1-python3.13-fips

Index digest:

sha256:adb18b616234560df524a98844eb44055894f54642d006dadbbaaec1fac99cd0

Manifest digest:

sha256:e96397bb9475c7dff67bb4c17e0b37ce1f31d3cdcd82b6361eb8a68ebd82fed9

Size

64.98 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:34be30feeb6d12645a8fc59ffbe8a8ceb56fa12566194686e4780e7565d74e75
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:6b06a966642ef6b89601eb6a56a97c4535f2c6ebcb15a2f4020267d6d3257ca5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/airflow@sha256:cf9c50f55d6fe5b2e1bf517181f717cdf47faa7def0422f31ed1e68eecd8f5f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:994cb3f5b8913ddf87e0363c3892826547dcbd36c58bcb9fb02283164cfc4e99
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/airflow@sha256:80230e6adc34f3145113cee2f57830881e4f36d087183e2fbc0662db39229f3a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:a1a6478033a00ea092279da7fb50065add1b7acad6429a1dc18af2878bdb3f44
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:454607caa60a647a14d08e92ca80a9ceca1045986b1eaed7245addcffb0fc546
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:836e346a985103b9bc4d29f563609d87604d27609c86ecae18fc8fbe5b5ba8e8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:1a94b818a9c9ac867ebecffec15da0bfec4822b7ef07e54ce6eaf86c7f8a2010
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:1a247c31f1f0a94fd83e9561bf89c1831da556f670b3e9d042b408a36e3bffed
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:685394bd67aa61e734ee5522c551b3b4414c28419542befc1bbb579646a73ad7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:c671aa11255ce3951d217828d74c78a182292f00fccd59e84a28482d6d1405ce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:f24fe382700e4ea68c65e82f6a65a6c93cf0f6528b250f9c1756e3a81c43aea6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:a33b61286408615cb879da507cd631dabf9869b8d4fc37de02b6594d3f3f2cf4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:e991c1373d5410397181a185f7f76c884e20522a2e0aad18a1c6b01f3e170601
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:228c74f2c0c4c178a31f6656e02c7425a11fe03a77b3fb3f16d2bd640d2d919f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:cd70fcf0b0972c621388d6df386e6ea87f240a4b9a589dd1d017f9b5cc8b9989