Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.7-debian-fips-dev, 3.7-debian13-fips-dev, 3.7-fips-dev, 3.7.18-debian-fips-dev, 3.7.18-debian13-fips-dev, 3.7.18-fips-dev

Index digest:

sha256:1474badd276176abda2290b78bda58741700aa72656e4a880f0583777b6c1174

Manifest digest:

sha256:f97b28c4c10c184ad134a48a2c2bc2016eb9011df753f8769979f51958773f4d

Size

87.53 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:9ca412192c76290df7a5c6e4554d1f51a41ab45e072730ec84475d9eb4b5f060
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:7ccbd2ccc7a7717229066b4a91d3d2039f219f10e69e295d63fd9b4d43582044
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocli@sha256:e7a63cafed1c822452f281624a08551e50dcdb8b6b713107ccbb46555239d388
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:7cea135d82303084f72eafff90aeea2812d9adce6b7dd19ab8288876764ef7e0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocli@sha256:e23c27c8b5ae2348ad823007a7545e2cd03768ba0e35ef8e9c3b9b08c6baac18
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:de2864bb14b2291f56800bb728c5ea80ac24930b4fde55a4016c8d99155c8df5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:39f5ec5f4f79c98f79210b5b48df7c405db23bc2f4b0b694eb203e378e3e1856
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:528e462f388d196e6f540fb0f5721fcd727498e973743ef08ad04782aad4952e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:5c90dea641d4a92565cc5c3a8e392561dcbc484a1c94c10ccbdd45e5c466d0e2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:1f10e5050d1a2cb8583bef3fafd248534a6b33862a2f97c45b6c5c0db5543d05
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:a00deca8a222690eb76d86134f972e6e451f1f18550788f9e63a544e11858c3d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:02579272b1431653dfc8e256472a06ae195e6582322e5ba6921d1a2db5a0c4a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:6bbcdeb251eabeaba3252671431b81ed9e95e9c7111178fcff960e3e062bcfe4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:d7a9622423d118beb6f870c4ab0896709ade41e7a953b3b35c8f7e64cb66a42e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:0d6c76e57b9c2fe731fb954e0316eed5afbfc64e94c64053e59a3b8cd8609157
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:969b4f049601ade84480c0d984affd210fae328d97f58b835caedf8f812f5809
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:648f967bfd25add510c77c0bc2e262dd14fff698f262d8f89c7d2b70aba070b0