Sign inSign up
amazon-k8s-cni

dhi.io/amazon-k8s-cni

amazon-vpc-cni-k8s 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.23-debian-fips-dev, 1.23-debian13-fips-dev, 1.23-fips-dev, 1.23.1-debian-fips-dev, 1.23.1-debian13-fips-dev, 1.23.1-fips-dev

Index digest:

sha256:49a7af6b8e645da218a95e935304188b8ef840a0c1cab9657fa54a666591250b

Manifest digest:

sha256:fe13e62fa879b754bccfdbab1638f3dfaf08cd4a47c44552af5abd09b43d2101

Size

90.71 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/amazon-k8s-cni:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/amazon-k8s-cni:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/amazon-k8s-cni@sha256:6386e9e2407edaf61ea1b6a98181922d66f4a5dd2399da6fdd1016eacd31645b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/amazon-k8s-cni@sha256:70da168a44b5e3f2b750a159bbccc103c78247bd6ff4447cf5282cb1787bdc9a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/amazon-k8s-cni@sha256:b8c6b15804f1651e4bc92712e078e600d7fe134afbd68befd2d2b13b1de5ed91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/amazon-k8s-cni@sha256:b234589fec28d34a2440ac67c1bac17af483a7ddef0c2878fbd617f0b5ebee62
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/amazon-k8s-cni@sha256:137670991cca3fa601216ba870f9bf4bb87cfa7e325548a496e59b087115c663
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/amazon-k8s-cni@sha256:98b23e8862813c0d3d0d3eac0696aa19c9982e4ffdcb3d103d659d670f3c04b5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/amazon-k8s-cni@sha256:469d6770def1e555597363348f846f94db997406992e3e7e5bea9481c724522d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/amazon-k8s-cni@sha256:4229a399c375e786c6bca8584680c94132fbd811738a988b41ff5e53c9732322
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/amazon-k8s-cni@sha256:ed5e6a95201097f0d77a858e4e1c58c691134e6ff4b085532d184671072c3a29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/amazon-k8s-cni@sha256:2da71242335c8d8b367d74f3e781f0cef97f0c959c835fb5fd279a316b1ea209
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/amazon-k8s-cni@sha256:d66c9f9587701918f07e0a9c667d7b9a4415499ebd520f75056c42c381a80eeb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/amazon-k8s-cni@sha256:ad69ebc5fa55bce132ed91cbc622996cd45dda8c647dc3940e06bbb349b8186e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/amazon-k8s-cni@sha256:4723421249759c5e1e5580b25b034b85d08b5a470fa2db3701c7142c8e8963f3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/amazon-k8s-cni@sha256:4ae54592cca4d0330793d825037cf9447de792303b7fc47edaec5f889e78f4de
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/amazon-k8s-cni@sha256:830d273047189484233ba1d2703737ff03ea490a12cafe94047d8964400ebe67
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/amazon-k8s-cni@sha256:4c08f320da8dcd54a730dacbb266a857defba19655d1da2d94d071e0c6f83737
SPDX SBOMhttps://spdx.dev/Documentdhi.io/amazon-k8s-cni@sha256:65eb2203e94524d4cde22e94007a0abe70acbe493bc64444218a2d42e3e8434e