Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 4.1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.1-debian-fips-dev, 4.1-debian13-fips-dev, 4.1-fips-dev, 4.1.3-debian-fips-dev, 4.1.3-debian13-fips-dev, 4.1.3-fips-dev

Index digest:

sha256:a8f1d765aae7bfe72d333bf0d22539efb442154488feea628ee8f0606fcabe66

Manifest digest:

sha256:b5531a04503a32d221d59d21faea3984f1124fe017297d4ea0dbe68e9b1208eb

Size

89.18 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:393c403661da4d9e2ae7ae17a93eddf685eb76036db3338cd75ef65971cc4cc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:700f4af0123139b1b4e21f752c045a429837b6b6790956051bb1ca75f2015407
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocli@sha256:5c656f62d0a6bcf904819780d73bc5e41f162a211af6c5513e573c39a733d2d6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:ba294051ec01f28d4af1330f69e8e17656b9c52bca0fa833ddd096d1a6df3038
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocli@sha256:c267460e71b0219009166480eee909cc0b9728bdb6fe87b1f058c8fa10f78eec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:2a5e579109bb86b07b0487e187bdd125ce86f498333cedab019fe668c848321b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:40e53dcc4da27f27b7bff7846369e1150a5dddf9ae92466fbc97393c62a1ad03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:2282b7fb5af2ac839297815870aad15d30b8a2b13f0dfb63cb64c034b5d4a21a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:3c4e45645b36c77bbd941c416ff231ec26b0706b1537b01e8485e89600bc6155
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:74ebd53ca08436ff0dcf0dd9a153138c857b8b04e42295489fc107cbbf3ff731
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:f7a46dbe7c176c0ae8948a20e656567bdf98f8a486021351e8b6af460bb558c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:0d70f97195ceda608c7a9f89caf822cfffee3085900dcee5fd9dfa22e108e926
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:72be2dedf616c8572a7d57b99cc98dd8d338fec4917ce588b9801cd8755f928f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:bd5eae87e7e309fed1706f9033675399f216063cf4c8f9f8d2d94f167908a2fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:c19d1316e66fad43851b4da5ca35d2508355d0561fce59ded9966de7f6d92be7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:97d1b9eb28d3120b29844f8ca7f885e91cb25c345c191213f9a2a26380643d86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:d8bbb2299c818f8ff6b7dbea7e9bab241f4c1a36c74271a87773bbeea3206952