dhi.io/argocd-image-updater
1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.0-debian-dev, 1.3.0-debian13-dev, 1.3.0-dev
sha256:5f73fcbcbe0999deefe9dd3fca7b3399e951c24dfdfd684f8fccb42ded7b3cd2
Manifest digest:sha256:36c02f8d0d69b971579c285aeb358b8355d07c355e662b2e530573024cd254fa
Size
130.96 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocd-image-updater:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocd-image-updater:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocd-image-updater@sha256:3bb61d376145415b0fd8c8648fb94a4d2d2c01e722c512fe73699d4adb50f20a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocd-image-updater@sha256:e37af7c322bec51701814ae763d25a8d9f407c403c31b84e25eee94ff545f048 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocd-image-updater@sha256:2dcad08ef5fb2a490f118366734599f2ed8ab37a46a00021768c6a44024f991f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocd-image-updater@sha256:6773ba58e5f59fda1df41b08254a87a653d25532d1caaae7468a1a73d4c01563 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocd-image-updater@sha256:1d0da52d170b49ca9ff2a908576c16b58a13e7e8cba94f1b7b5a7211cf56b40d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocd-image-updater@sha256:891cdb34c8b6a041815ecf1a22fe024174096c684e6beea034fb4d167916ee2a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocd-image-updater@sha256:2f4de355cc61923ec78440665a2bd11722347f50344b346da6f398af9b34ecd6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocd-image-updater@sha256:5d8d68634f39685f7d6a7e80bad794832be7eee2776c5996615edefb51caf3d5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocd-image-updater@sha256:86323db530f9399f9443c35297b5381b120513dcff0f36f67ebbec6062d2d820 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocd-image-updater@sha256:c0e5163c2c449125bab83ef8b09233d6664834e81684ec955e5b73c1bb257209 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocd-image-updater@sha256:60adc09c8ac0f249edaa8684416d594a0026a31feb8aa1d8c011e436e7d9c5e5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocd-image-updater@sha256:1ee00e83facefdda97b6c0555e1efb2bcd30532793593936b3e4471058367e44 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocd-image-updater@sha256:162e84ed6a20b07467990c2c77262dca3e6aa9762167b272f89fe18decc3fff3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocd-image-updater@sha256:8266ef7ecc53dae2092adcd3a5ab65eb3e36c57a30c61a7ea5524fae99950e94 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocd-image-updater@sha256:d766ae0ca372273e2d1ce87063875337afaad00c95cc735e8d38c2efc5282b13 |