dhi.io/amazon-k8s-cni
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.23-debian-fips-dev, 1.23-debian13-fips-dev, 1.23-fips-dev, 1.23.1-debian-fips-dev, 1.23.1-debian13-fips-dev, 1.23.1-fips-dev
sha256:49a7af6b8e645da218a95e935304188b8ef840a0c1cab9657fa54a666591250b
Manifest digest:sha256:fe13e62fa879b754bccfdbab1638f3dfaf08cd4a47c44552af5abd09b43d2101
Size
90.71 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/amazon-k8s-cni:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/amazon-k8s-cni:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/amazon-k8s-cni@sha256:6386e9e2407edaf61ea1b6a98181922d66f4a5dd2399da6fdd1016eacd31645b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/amazon-k8s-cni@sha256:70da168a44b5e3f2b750a159bbccc103c78247bd6ff4447cf5282cb1787bdc9a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/amazon-k8s-cni@sha256:b8c6b15804f1651e4bc92712e078e600d7fe134afbd68befd2d2b13b1de5ed91 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/amazon-k8s-cni@sha256:b234589fec28d34a2440ac67c1bac17af483a7ddef0c2878fbd617f0b5ebee62 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/amazon-k8s-cni@sha256:137670991cca3fa601216ba870f9bf4bb87cfa7e325548a496e59b087115c663 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/amazon-k8s-cni@sha256:98b23e8862813c0d3d0d3eac0696aa19c9982e4ffdcb3d103d659d670f3c04b5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/amazon-k8s-cni@sha256:469d6770def1e555597363348f846f94db997406992e3e7e5bea9481c724522d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/amazon-k8s-cni@sha256:4229a399c375e786c6bca8584680c94132fbd811738a988b41ff5e53c9732322 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/amazon-k8s-cni@sha256:ed5e6a95201097f0d77a858e4e1c58c691134e6ff4b085532d184671072c3a29 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/amazon-k8s-cni@sha256:2da71242335c8d8b367d74f3e781f0cef97f0c959c835fb5fd279a316b1ea209 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/amazon-k8s-cni@sha256:d66c9f9587701918f07e0a9c667d7b9a4415499ebd520f75056c42c381a80eeb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/amazon-k8s-cni@sha256:ad69ebc5fa55bce132ed91cbc622996cd45dda8c647dc3940e06bbb349b8186e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/amazon-k8s-cni@sha256:4723421249759c5e1e5580b25b034b85d08b5a470fa2db3701c7142c8e8963f3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/amazon-k8s-cni@sha256:4ae54592cca4d0330793d825037cf9447de792303b7fc47edaec5f889e78f4de |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/amazon-k8s-cni@sha256:830d273047189484233ba1d2703737ff03ea490a12cafe94047d8964400ebe67 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/amazon-k8s-cni@sha256:4c08f320da8dcd54a730dacbb266a857defba19655d1da2d94d071e0c6f83737 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/amazon-k8s-cni@sha256:65eb2203e94524d4cde22e94007a0abe70acbe493bc64444218a2d42e3e8434e |