Sign inSign up
APISIX

dhi.io/apisix

APISIX 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.18-debian-dev, 3.18-debian13-dev, 3.18-dev, 3.18.0-debian-dev, 3.18.0-debian13-dev, 3.18.0-dev

Index digest:

sha256:087a1f580bf2230336923c3dd8e1da687e2145d4640887f8c7948b7f6e2aa025

Manifest digest:

sha256:884635886eecef02698b4580ad1e202fda206089a5a13cd59afc849a55f4dc47

Size

77.93 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/apisix:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/apisix:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/apisix@sha256:2cb4520a2528f5d1572af05a250f0fe4eccdae29de545ab76bfb5576f612090e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/apisix@sha256:4512d9017f858110b9220942b3b2c4f8709ce991d52be1b70162c62aef30e0fb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/apisix@sha256:62502b583a455284b9c57249a3fae2db6a3ca7dce77620974c056c2dc1cf9c7f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/apisix@sha256:a6bce22fc2a29ff1a25e89816f6bccfb53af83d72e8b4c6886b3cc55fadb6dd6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/apisix@sha256:3de385095dfcaa70edc915a60be906794d6e0b3623dc3c7021dee930133bcce3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/apisix@sha256:14e3cbab154cb1d618c8bb565cb366c917d2aeca64dfa158102a5862048b5b46
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/apisix@sha256:1bad5bb96e64dac93471f0e92e3473814a3b081d571539d44c11ddffce50319f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/apisix@sha256:12ce4affcd4e3187e0b62b25e04800ba38b4c2c3b649bf5065f9a8a295cf3e0b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/apisix@sha256:63e4ec50639b8e8cbe7edef89397398658e4fd1316d465e16dea450c32300758
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/apisix@sha256:45cb5ed70c42701b342d9f22aabf5a993bd56ddb6ed0804fb96203a4942a40f3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/apisix@sha256:8d0461892cd52f3b2184a62d773740e9b7ed98c37f0ad7badc37db2c0c5ec9ea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/apisix@sha256:18e965be539beca23935e7a33ebd755fe2f33cad8d36e5c47dc75c36b8b3987d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/apisix@sha256:8ea37ccdf32811287c57209f724a3e95686f5f844d7977568346ad09458887e3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/apisix@sha256:b3d85bcd657bdde531fa35c7fa1b886711065e660b1ad06628c217339e3ee9f1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/apisix@sha256:7cec7bab83fbfae979574333b001745cf6b5d4c6958f2ba3860db484b0e0c090