Sign inSign up
APISIX

dhi.io/apisix

APISIX 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.18-debian-dev, 3.18-debian13-dev, 3.18-dev, 3.18.0-debian-dev, 3.18.0-debian13-dev, 3.18.0-dev

Index digest:

sha256:6babca3286551cd7be5522fc931fa85d7c103efb5c76a64ef5c6f0679069cd9a

Manifest digest:

sha256:8b56dbc3d459b9d77361d6f4ac96937de24267c18fe692015ad02a19217460b6

Size

77.93 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/apisix:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/apisix:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/apisix@sha256:3fdaec08bb3f761fca3a70aa82f10ae2c4ded94c69045a8d02a5d45d01f31a0c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/apisix@sha256:13b2fe972746f599392c93cf14415ab3c98c3648a784627b9e00df8f466b94b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/apisix@sha256:c2d8f2bf8beb47aac417fb32898c483d94c9f0e3878bdc3cb090d4857f246508
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/apisix@sha256:2faacc920d794a16accfd20b5e856d018e92bc67fd66e0d5c3e729770fe1923f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/apisix@sha256:cc77844a9714804ad4e8d313e2c6a684a47c211975e5cdc22cf2384403d5e354
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/apisix@sha256:c2e9e6783aa3889b6369ce92a8cd58ea59692d4ccecc5c0aedb3729aa08c6d9a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/apisix@sha256:3221b463798154ff45646435cec0a4746cacd26a96ea11caa694fc59adabb798
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/apisix@sha256:579a80bcbf1d381166446e364f8879a24fcc10932c5114e22b32face42da35ea
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/apisix@sha256:b802571a9f090181fdd863e884c83a1c0d706fc888b2095d5ae4984f03795e12
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/apisix@sha256:97e70b398def252cb4fed714428b35c3af4fd070f2a92352ec3d9f9073070061
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/apisix@sha256:d46cf6092a6181ea05ec119bd447653abadaabb08e31043a7a3c6b34bb5c2bba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/apisix@sha256:b7d1e6f29f5970888ba7d2f4e255ce924997f855f3ceba687ddef2494b725db9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/apisix@sha256:5689657b7899e776e2b5cd9b2c600b0b4e406829b6c06ba3e3193793f9b17de6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/apisix@sha256:ac72d39a8ee14b22f3eaee51e15a5eba5ceff56df440c85447528b6da4201d89
SPDX SBOMhttps://spdx.dev/Documentdhi.io/apisix@sha256:e858d396fdeff12adfea4e886f573596c0716db1d6c0e0d60d15ccc2d7b7f6eb