Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 4.1.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.1, 4.1-debian, 4.1-debian13, 4.1.4, 4.1.4-debian, 4.1.4-debian13

Index digest:

sha256:8c400083876e4cd7f5a90e05ca021743013672be195deb8aa407dbc1446ede23

Manifest digest:

sha256:9f59097dccaaa23b7172b3a88b41c2b0359f2f7acda0bcd1ecf5cde12e47423a

Size

73.60 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:b1d7b5bf952b4d40eec70c856c61c1c115b411d86b38be9f6efc2553e7e5095a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:69d8b879ae2650fe559cd4be72216f73fa01d7fe839f52ed7a9c077872b37572
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:2e50efa1024c2ae5382c483702a1dd734163e680d9359b1244315955b56c9d0a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:2cbafdb243feb742d4f41c0248de874001fd907c2c1bbf69e3e5c3ed0c5f2212
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:53ab861aed81a4a3a8928caeca9b7eb560abea9898233fe2c43ae0ede9e9b2f2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:12fe48f6107d4f8bb7c84f8a26a9aa48806bae13c43bcb684c8b42c6f18ec171
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:bfc9ea66920ed0aa8b08bc662268265a33755f8907a04ca5516f456e94b5948f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:97370608622264d06b208988420a9ed4f9b314fbb40c5a1af17259c9b0b72cb9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:4b10e847f08cb15a9f5e8b8e5a2b10da268f6b5d4ce2cb8348e3bd6c39d7d711
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:25c35d28559d75cc063fcfaa989cd5ef20591188b11f845fbc549fdfe80516fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:ba8d369f2612b09f4ddc82d552cbc897ed7bc1732d19b021f070b430903c4a63
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:8e2f873339849e8be0f1f7db99967d1bdf293025c4a58e9021262875db794cbc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:1b14ad9ebc95cffc547037e935fd090e907d4d77bfca1c59e55fca6d6fd83e0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:1486944f0579f61aeeccaa8721cfdc567b31d352d7004a1ebe60b400270e2881
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:2580c32826482127515499414185769cca5416b72934891c2d95b0903ebc1a3e