dhi.io/argocli
3-debian-fips, 3-debian13-fips, 3-fips, 3.7-debian-fips, 3.7-debian13-fips, 3.7-fips, 3.7.18-debian-fips, 3.7.18-debian13-fips, 3.7.18-fips
sha256:db74d38d00562c605a3db0698ed5c15296178a33bd9aa2687d68e10e01fc6ad2
Manifest digest:sha256:26e8ce085b0b45d350f617d2b7b751bedbc8a398eb1679419fbd3f410382c215
Size
72.35 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:081a5aca8854745007ee6757f4d9e783140f89037ed9a77d5c3f2bf7d04a6ea2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:d5b69bcc237258dd07791fd35b94d9d868e4f195c1cf7c8ac25fa285bbd7bf6d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocli@sha256:00d2363f95fa51adadb716f417faf33a9ce01ed993c7bec9ca09a2d06a5bbbf8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:6ffb1c76b503bef743bcc14e3546d19a2d2b2788ead7515ef93cc3d49eedb3c0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocli@sha256:4dfb23f6b5955665e2b2b5b6238f4aea2370f622191f7e20c5ec214849ad5000 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:f7414809bda56362c95d05f78df8ca39e64de2cfeb1e6fbc5acd7f290be66c8e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:e5ac40d4c61e5005adcdffe5b2e955640cabe520c73e2df85f4c35e1bdfaa0af |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:6468ff20dd25a89436570ba5ddf2a0fcee4648d337cd871469bd66adc3d7da73 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:0b16e965c776b7cc9a0e9e4a8120660cc2ac5e0cbc8174ca766bef16ceb1e7e3 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:ad1ac1f2cb071bf20fd7a43b88ece1d0161cf91510524fef17b81e549246c6b2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:cfe70999f6bb681fae6560ac657adc5fa7ed3d499a4e081e2ea22754f237e0b2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:571c17c972df80fbb8b47f941a0e36dccac97ace19020bb7e2a9d62721073a25 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:72b799e10d641c40573b64820c9446e4bf00be6a2aa4f91591e8b64bccab2e8c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:d151b77e0b312fa0dd55d0ada5f63f06053661467e92c1e95c98e450cfaf656a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:a15479a5ce85c7788e58b39eefa26f17d837e612342815889e944221be4a1a01 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:b9136b535b42197b386fa5d799360f7f87f1a7bfad91f513c26a40cc892f91e7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:631bf9f8e6bbe3ba8cb85bcdf34a9a5a84ce81312c3787df5532d446ecba0ad0 |