Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.3-debian-fips, 3.5.3-debian13-fips, 3.5.3-fips

Index digest:

sha256:eaeccacc054f262da9d8b6e726e3b7e8628b4d793c01d3c57b432ac4d75a8e49

Manifest digest:

sha256:b7e1c783916b4ad70cbb57ffaddc38aec91a20dbc07a0323be94427b10e7b212

Size

117.09 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
11
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:3c95f773a0ffab3c42b97df9b128d740611cc16e78a92445d67c1821128bcba3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:a2d746fb96073f38cdef8b1833499cba8ea04a4a1359e995d4d50e6f495e02ad
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:2e133b3c4fa61dbe836807746fcc7582471d5e613a5ac6460c67bdf74c73ed87
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:86fd8cfdfb174249fba622cb461f7c68e2f6e794b80a0d0e77a09e4f0718a243
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:f5c5f069c5c4e89f8c5918010920935117a5566546f932479195e64ac5e762d5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:521388d16c653c77cab2ab67ee06de4ad49de0b436a0170b3751d256a4b4a57e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:d18b1499b966cf36deb8153d151d0145893ec2befa07c3c79d4d28b6a9b4ef56
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:7fd5fd19181b4b8ecd5f902847203827bd192425f5d7137adca214291c1afc00
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:4571d130dd99fc72acf547af58aa7d103202ae72359e18c9cc3d6dd6f0e8db40
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:44037710f5af2293609758d31accec66da7266c3f5c6912e299db670d0802052
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:65044ed2db37420bbb0f416c519ac911fbf563280efb51dd345fea84c932cb21
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:9b9148ffcf36cb0a2a8b92457b31d1b3615518dad75146d9a58a447892baf1b2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:5a0c49ed549542f0ac8bd2902d1cdbe5cd14ce6871cba8283b69b347bd518d58
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:57281984e76d9de4a48a32e8ba35a9d4d1702eae2987a91ac4e6f09a0ffa22b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:8f1c03ae6ca5fa3860c712d9d28087aedc0c971322b6e7d00a2ff197113a4155
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:5cfd271094dd88d1bea3aff331fc3e284e6d802d5f753988e186b16cf0f36162
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:90fbfa52567d6f8c62ecb3d9b87dc305acef6f6d19728f4429601ca6d44785a6