Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.8-debian-fips, 3.4.8-debian13-fips, 3.4.8-fips

Index digest:

sha256:ac5b9f81ec797ab7fff96acf69b3c6bc5121d0ef95bfda63ce4744043020348f

Manifest digest:

sha256:2e43d604e9e1370a4ef00ecfaf04db71e33295676d7a90f91dab8bf447ba7a36

Size

117.32 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:1d49d0e4a91546158a79be45ed10999d5743bce89eeb6d8fe0877b862330f882
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:7c3c5f9499eaf05fd73c21274e9bd07b845de16c8dfc9409341f4286418337e0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:90bb738138961cef183123654da069b388c5585c156b627ddb38a99449f45358
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:497bf679a0439ee114af577dfb99e00aa68dba518af4e6d734eaae930d33d253
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:618695295affb9342d58c742460ffb64ac1bf331b7e681a2ace36f54288c166d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:aa75b93cbfdb041a5d11ae542a9369be3fc13c36d4c0045f1eebe6376c989f8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:9441d44a303194a0595ef91971e26798a9a37bd3214ab28a06b23647a5dc4f5e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:eb1c656d153f493a085d7352bf2b11e72c411609a8cb40f8eba4dcc5e9713ca5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:efb6bbbf8c34d1e82941c6214518e4cbbaf7c0a2c2912e8d344b315d101dbf55
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:a75d2792ee5fb28876ac845d3b91bf8a84048af592608633fe3140d2c9b848f9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:0d2ad2a793a02c95b01021d73cfa8197d9daacc076bd2d56f6d65df90bf5e0b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:703baae4c17b234ac8eb73768148026af27080b02a68b463835abd504f434d77
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:e25792c6cc03d1310df90190969639ae8431e0f157ed8efc17ca4373035ab8d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:5cd3d2f96cb13de259c5d6e9ff060dbce2a20b6182e0fb6f03d49797457e8a2e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:074bd6d3d84c12aa30d3f503519c2cd26f588d494a13c710da7a7d5d1e8edd75
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:90c5e8d84822eab290297777d5cedfbcb47f4497601e7dbc409a4fb8b5ce06e2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:39b4abec93a1b78d8ccf812afdbb48f3b411cacecc5a866f4f70f41f8726deae