dhi.io/apisix
3-debian-dev, 3-debian13-dev, 3-dev, 3.18-debian-dev, 3.18-debian13-dev, 3.18-dev, 3.18.0-debian-dev, 3.18.0-debian13-dev, 3.18.0-dev
sha256:087a1f580bf2230336923c3dd8e1da687e2145d4640887f8c7948b7f6e2aa025
Manifest digest:sha256:884635886eecef02698b4580ad1e202fda206089a5a13cd59afc849a55f4dc47
Size
77.93 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/apisix:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/apisix:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/apisix@sha256:2cb4520a2528f5d1572af05a250f0fe4eccdae29de545ab76bfb5576f612090e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/apisix@sha256:4512d9017f858110b9220942b3b2c4f8709ce991d52be1b70162c62aef30e0fb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/apisix@sha256:62502b583a455284b9c57249a3fae2db6a3ca7dce77620974c056c2dc1cf9c7f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/apisix@sha256:a6bce22fc2a29ff1a25e89816f6bccfb53af83d72e8b4c6886b3cc55fadb6dd6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/apisix@sha256:3de385095dfcaa70edc915a60be906794d6e0b3623dc3c7021dee930133bcce3 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/apisix@sha256:14e3cbab154cb1d618c8bb565cb366c917d2aeca64dfa158102a5862048b5b46 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/apisix@sha256:1bad5bb96e64dac93471f0e92e3473814a3b081d571539d44c11ddffce50319f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/apisix@sha256:12ce4affcd4e3187e0b62b25e04800ba38b4c2c3b649bf5065f9a8a295cf3e0b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/apisix@sha256:63e4ec50639b8e8cbe7edef89397398658e4fd1316d465e16dea450c32300758 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/apisix@sha256:45cb5ed70c42701b342d9f22aabf5a993bd56ddb6ed0804fb96203a4942a40f3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/apisix@sha256:8d0461892cd52f3b2184a62d773740e9b7ed98c37f0ad7badc37db2c0c5ec9ea |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/apisix@sha256:18e965be539beca23935e7a33ebd755fe2f33cad8d36e5c47dc75c36b8b3987d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/apisix@sha256:8ea37ccdf32811287c57209f724a3e95686f5f844d7977568346ad09458887e3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/apisix@sha256:b3d85bcd657bdde531fa35c7fa1b886711065e660b1ad06628c217339e3ee9f1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/apisix@sha256:7cec7bab83fbfae979574333b001745cf6b5d4c6958f2ba3860db484b0e0c090 |