dhi.io/argocli
4, 4-debian, 4-debian13, 4.1, 4.1-debian, 4.1-debian13, 4.1.4, 4.1.4-debian, 4.1.4-debian13
sha256:8c400083876e4cd7f5a90e05ca021743013672be195deb8aa407dbc1446ede23
Manifest digest:sha256:9f59097dccaaa23b7172b3a88b41c2b0359f2f7acda0bcd1ecf5cde12e47423a
Size
73.60 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:42. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:4 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:b1d7b5bf952b4d40eec70c856c61c1c115b411d86b38be9f6efc2553e7e5095a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:69d8b879ae2650fe559cd4be72216f73fa01d7fe839f52ed7a9c077872b37572 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:2e50efa1024c2ae5382c483702a1dd734163e680d9359b1244315955b56c9d0a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:2cbafdb243feb742d4f41c0248de874001fd907c2c1bbf69e3e5c3ed0c5f2212 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:53ab861aed81a4a3a8928caeca9b7eb560abea9898233fe2c43ae0ede9e9b2f2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:12fe48f6107d4f8bb7c84f8a26a9aa48806bae13c43bcb684c8b42c6f18ec171 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:bfc9ea66920ed0aa8b08bc662268265a33755f8907a04ca5516f456e94b5948f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:97370608622264d06b208988420a9ed4f9b314fbb40c5a1af17259c9b0b72cb9 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:4b10e847f08cb15a9f5e8b8e5a2b10da268f6b5d4ce2cb8348e3bd6c39d7d711 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:25c35d28559d75cc063fcfaa989cd5ef20591188b11f845fbc549fdfe80516fa |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:ba8d369f2612b09f4ddc82d552cbc897ed7bc1732d19b021f070b430903c4a63 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:8e2f873339849e8be0f1f7db99967d1bdf293025c4a58e9021262875db794cbc |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:1b14ad9ebc95cffc547037e935fd090e907d4d77bfca1c59e55fca6d6fd83e0d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:1486944f0579f61aeeccaa8721cfdc567b31d352d7004a1ebe60b400270e2881 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:2580c32826482127515499414185769cca5416b72934891c2d95b0903ebc1a3e |