dhi.io/argocli
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.1-debian-fips-dev, 4.1-debian13-fips-dev, 4.1-fips-dev, 4.1.3-debian-fips-dev, 4.1.3-debian13-fips-dev, 4.1.3-fips-dev
sha256:ca396d6d26290089de4bbdfa6326c5f0f24dcc5df2e20298e0cc2096e3b49403
Manifest digest:sha256:1f88abc4f605d249a019135d3642f7d7272ff36d058dcbd81d1ef690e3a73a8a
Size
89.18 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:04e2a027e5b0fd724187a82bb0c7f1e2b6925307fb71bc5fd8e3b16b7115a65e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:f5d2e79165c05e830f24d1f9941abc0770288af08773ae1de4d3084751a2bb7b |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocli@sha256:a1edf2b687619881bc0b965dc85fdba780136a0c0f97de2cde3522ae5cc5e0ec |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:970da6d4e9a1488e698f73a988b473c029c93ed4af86e7c2e07da22c3197dc24 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocli@sha256:15335dcdf0875fe6638876ef0db1eb6b7f645c848a435bf44e6006c73e51d51f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:77955dcf82284d5dc9fba5da77f7d6dde67e4a61c7d252f60a0a36a3bc2cd924 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:9b6d53de5405f363832b3e3256519fe3200a2681ccb668120bcb49d46841df3d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:da11bd7249823ebfcf21e254de2de62071719ca46be3c6474c3d2f5281cab045 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:c642c6f4c42c26c67e9d5d3dcd42de19ae18045f3376f54c1c0fa5b2611abab5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:d351d3c913facdff351995c36759ec50b4d09f2f01327bb8b647578500a4109a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:b68a84cfeb03c221a48ba70d1516c062e4f9c37f088b10affc63acf937fec95c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:7b381bd781cfc1bd6a798bdaa5081f40bca034d2e1467bc69647dc7bda5096c4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:cc9d18935e4c7004523e23d13c9ee0aa093a718e071892e791a29bdfbfdf18f2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:f5069da26065f0a12a6756d272e130fae3dabe22241e3075526ff143cdd5dc35 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:049a808d55baea49225dc6017046d9df9e02592536370e59b297fbf2414ebb9c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:8780513a59a0d483bed1ecc170ca5b7f1d23162e01e44d30b9e960fcaf71e43f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:39641443a04e8824912952f576063c42bd5488a761fe7b0f5f1a62f464819532 |