Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.3-debian-fips, 3.3-debian13-fips, 3.3-fips, 3.3.14-debian-fips, 3.3.14-debian13-fips, 3.3.14-fips

Index digest:

sha256:2c6dd712f3680e3adaa995a71ba247894ed817794f0f5b0863b8199a7595cf3f

Manifest digest:

sha256:958338ee256b591263cb38c226691f0e499f0710f7ad0faead2d993148e5f152

Size

117.02 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:c1542ad806c7fb43f1362e8fd17cb99d759cbd0da22e81b7a720a9fde9decbd0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:5c6c7f673c4a2a7d2fa780daaa73ddfaf9efb52e1a0b0ca8357ea46afe0b8bf0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:f6fbdc320b20518e6798320fce191b8221097d3212b67e4c4dbc40d5cceb56c0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:a1edd44037677a9a27f4b55d9ec204ccf1471d6e055469e4f0ccb40dda48b78e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:176d265472f3644faa1f9b88bec64676f0077e0c3eedab7b8f905176c13ac526
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:277341f008b53c46a402ecdb0f8e3ce6584c6d7c1eb141b444c913740bf8730d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:29c86b68716d934e2e4e9be0123b39b3b14be956a4b32bb716c6d2f118cd5efd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:2fa7dbdb105885b60e0f32935028ad17a47f2ac2a3c27c754c9fce69dff81fc0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:89f55c7d1c41873b824c112b9c72605c66e39dba12fc4e9a1e3451a28d013d6a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:dc8ff06bf313f03185e3932c47503a67c9dab3e5f4dad609a10879962d05d5a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:3631f652daed0ac59f667d3a3e2d93b80f7e86ac0be1f4e3e589d4801e923e11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:5b78bed7e9d60e7131538a3b0af045e0a3f4657e15f8a329f4f913adfdcbafb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:9d89ed8d5c319d79e43dbce411b0ee07b973972584f714db1746531874080075
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:63214e835ec3458023818592a408216527bd53053ddd6b36ed962445fdbbba37
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:5fa69297cda61124a32178809a6ecdd76e9d24f708455f8dcaa753546bf0201e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:5f171e118a6418b68ff2f97b980e2f65aee286e9228a70682747725ac0930aca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:f3578a6ccb40053cd896303618bc8c613e87e471ea8caa6bfde20a8d6d6f928c