dhi.io/argocd-image-updater
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.3-debian-fips-dev, 1.3-debian13-fips-dev, 1.3-fips-dev, 1.3.0-debian-fips-dev, 1.3.0-debian13-fips-dev, 1.3.0-fips-dev
sha256:57128c0a7f72925c8666e3541ec55c04149cae3f32c412b447a820824f405191
Manifest digest:sha256:75844c4fdb8196b7c5e00cd946268968d78069668dceeb833cc9400baa9822b7
Size
131.82 MB
Last pushed
1 hour ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocd-image-updater:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocd-image-updater:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocd-image-updater@sha256:da29f24d5acca69e76462b1ced37b7f417aab9312694345c358c75dbcebd2b13 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocd-image-updater@sha256:be1b067b88ea2214e5de7e55a316576b5e52fdf42ccb67e77b34f621acb5cf11 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocd-image-updater@sha256:fd792f272c801efd29e7f9c70a07d0130bad641510f49c7627f138e26946332d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocd-image-updater@sha256:22b72ebecbd79e44226123a041fc94c526bb647d14bf4259131e5aa7f7c7eeba |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocd-image-updater@sha256:c50e73e9c1823ce5958e6f9b0fa145f399e2402ec5b83c044f7bf964fbfb1dea |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocd-image-updater@sha256:2680bbdc772830a088c2f601cc3566e42a1b1e88c0583ca3592daa66ef0b216f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocd-image-updater@sha256:45f03034b71a6d1b582911cbb4adcdd28c54dbf9b4f3a4f6df81639ab7006070 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocd-image-updater@sha256:0f6efdabdf42225c6ba62ebe6628a514665b3aa303f1cb595d22f43030806991 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocd-image-updater@sha256:7cfba82d3a2a6639a87c42223457cb2cf55f687f68126672b0445680380709f4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocd-image-updater@sha256:c57f9b44a3f4d43b6fc5bf9e0c29738d8e1c0322a5e28cb2d7c09dc558e069af |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocd-image-updater@sha256:ff995308af804a06c2610916104d21f760f043aa299abe87ae7415b6f39b5fcd |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocd-image-updater@sha256:93fafed0ae2aad4a3c0c53c9b3bb6d06d328c7a94deadf33e4400e5a4396594a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocd-image-updater@sha256:074ab2ce20967e49cc07693ef7d45dc264d01e64b8fce18d3d310a2b1e107352 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocd-image-updater@sha256:d5e3923c54bd0a69c5059d37bb29a0028b0cfe85f088f1baf22d0ef46e32f2a4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocd-image-updater@sha256:72c9d70e39b0cfe78a18e9aebc0577146ef2211bc45e0112eccd237505de71e5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocd-image-updater@sha256:fdc7e67db89ea9a415a44fdc1d2e2c82fee5bdb0943d6b645d4e8bcfc17fcb52 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocd-image-updater@sha256:b668296f02a44534face5c9632c2b85ddd7aaef5f0cb22cad7394c655059c596 |