Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.5.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.5, 3.5-debian, 3.5-debian13, 3.5.3, 3.5.3-debian, 3.5.3-debian13

Index digest:

sha256:81d03f05d08b2325f0c9fa4a0281174178c544b0e39494613c6cd326f538efbb

Manifest digest:

sha256:0ff2938c2d53830f962a948da007d14159761086deaa25fa2af6f51e2a260ce6

Size

115.01 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
11
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:33d7341dd017e6b52e087cbf2ffca30a3e8d250de6df77ac04ea258290b66686
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:64b638e4fcaf4af872ab7fd873852f51e347aa905a426cc921f51149cd833d41
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:9620c5f90350dda05c0b9e7b6449b90dc073a562ea7e15492ee1daa252bd8b93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:2926ad14d03658c3e563fa60c3a04950e9b0e3a8497da8ffb779f28056fcf5f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:385550fec00c1bbf08f3729c3e81e8ec14ea63b259b1fbda96dc42a6cbf9ec2d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:e705a09d7fa550747a4fe0dc73dee187937fd10ab684d787d377bfd76b0ac60e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:fd5d0d1233b044bd165552cc834f4d4b535145081630fbaf533b661866e6214b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:784ad87abaebe6d9f47897758779cd189460de07007d38eeec6c84c733f23d35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:fed5ae3d856e170a2eff39ac4d390650f5b17451d73b57d86062e556aba114f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:9f45ed65bd69306cb89b11ea15c632caeced948303a49da8147b7b990dff396a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:ff9fae19a7a2825f3b48fed6d8daaa674e75796d66f080f6b8d33be98564caa5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:8db9746560dc828ca02b876e22c0590cbd36b0730525f86ccc23ddd60398d171
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:6c78b4b92c3ea22afe2e4f480659a6c2f1c34af108215fb85fc0649a7d001ddf
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:550bfe9960e1d93a51bf3a0286384e1646eb8edb2a96b2af31e28da9c7e0d78b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:c83fc502906f2911b643d2594f5176af3983e7a25c12c1a545501a52640b517c