dhi.io/argocli
4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.1-debian-fips-dev, 4.1-debian13-fips-dev, 4.1-fips-dev, 4.1.3-debian-fips-dev, 4.1.3-debian13-fips-dev, 4.1.3-fips-dev
sha256:177065da9077ba8d97bc5bc415956f0ceeb49c9e2f2c5b647cf664c4e4f6085a
Manifest digest:sha256:5ac23bd1de8cf6e1f23896cb7ace9933b7d9c6f520d96b77c9162afc73be568a
Size
89.18 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:4-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:aca9036218a19e321fa98831713098d38f3be70124395e0eff2d389f893da886 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:c1ea14e89d08fe0a2819d45b68630213c23dcf2f951594995af107cc1b206dbd |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocli@sha256:5882fc123931e81d3788cf4a7c026f2133d35475d8b414052fa64e06e9a90931 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:625bf0c62abee2759bff05173c7937480f1f01e1c312e8a2469bcdd844a1d4c7 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocli@sha256:192a8a1db993570a26a2b5c57819991d7acf20ed91268ffee380497ed032d9ee |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:28ac3a7117bc633c0954e3bbaf078394b6c11eddebd1f7212ba3131a5927221e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:07810323ab683edc16b59745be72dee0b5210b5f2ade283c2d8f0d49ccf22394 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:0bf998642d57e3552ffcf3bb2ec9309b3792037618303731cb2b42a78e76252d |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:9b3b29ce953bc3ca4c30590410b2e818c01c949806dbfc5f79334dae5f65e9a5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:0e8755a53270117d322c9e41608ffe18c5ee56c79a97437842bc86b7da92721a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:e711f0a8993a944d9c321e1e7fbc00af8a856f26db7fd947ec6563485aa6211a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:896182433b1b400ae84951be762c8f66946e11dd0cc5f2d3000fb135d7134b23 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:a0a3aaa7ae1051a9cede401f678763da9b4b880d80f3e55c1a4e09863581fa9d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:5c55a3bda793812639e1aa0d6fdffcc7f06821a48f969a2d00bffc002508d803 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:0d4eadf7a8726f5ed8d31267f6b7ca35c2e236d19aacf696ece782e6ec77f233 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:85b43055ca34b4810dce4821696f31a767fd4415b49f3bc5ffdba1a48ab2ee5d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:092fcf114c2aaaa80060376f991f6c0a20088c4aaf359a7d46cabf5683de4af0 |