Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.2-debian-fips, 3.5.2-debian13-fips, 3.5.2-fips

Index digest:

sha256:5ed79ba0147ed4e69a17160f225b235bfec998f6dbbb077f3cd3b38d087e23d6

Manifest digest:

sha256:6dd2439d696f2f2a133e48ae9796abea39443c95907f33fa04163f96e6463c12

Size

117.12 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:d3538ab1c734e780981220966174cb86742e2173f1696e84f58fa4577c1832cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:5f7a4db5118d73a4d81b40e4463f0c92248dcec921fa1cf957cf93eece6c10e1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:0d81bbca8acad38a6170d90e63beb3741e39ee17a817edc1b3d693b1cc523554
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:516fca20eba897bffb943fbf86caf0814626ea08d5117578a5cd97f7af857a1d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:5e7e081f6bcff5a7788e2b86865f67c79bd744537aad4085fd5f8caac0e2e593
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:2a851b48dc3935b64626827da14e72ce6b8b057c4eddd69bf79a333a0047032b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:3431504638221b58c9c8dfa17da5bd78aae8ed0e5bc659ece5b1ccd868ec66a3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:cf8e946796fb4a61a412bd7a5dd62ff890e2286984d4a0e37d286dea6619d10e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:dff448cc4460a88a6f9621c2a3c616bcc2a1ec7b46e47b963e40ed49257d6065
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:16ff4603e19502970bb66f959f0d344ca5cc8ddd79952be985405257f3b44b53
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:3c55e59f6d0673039232a17390371a043c3b37c13bac65c33fb57ecd1eb123b6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:241ff9575f8665051fddfc426d51bf586eac4230180ed849aaf967365ec01e9b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:0b4001d96cc2515e74c1a3bc2fff62742418307165e8737a526f248bbdd80844
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:be8df8ecfda3ca30df1a64398d6333e64b754c7c9c8621f7097be36e01090d54
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:c416781deac2c6ce736b7994f2234b1aefe32d0a7d2cdfb2b76596f0107bacfc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:83c941a5ef06693d7cba56051667f063d440fe8f4d97e7efb77e5c855e418992
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:67f77cba03519f8d2f605214cb7cfc31970b4713e02889ce45e4e2bc627b1ade