Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 4.1.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4.1, 4.1-debian, 4.1-debian13, 4.1.3, 4.1.3-debian, 4.1.3-debian13

Index digest:

sha256:55a1b47ea6a803f6501483608db33f55b6787b1f642a2f41413427049d473fd5

Manifest digest:

sha256:c3edc0661a526a2f2cd1d6d95ab7605a6484439c71336445763fd87242859656

Size

73.54 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:a49a3d9c3e76a2870cd97aef772ca3c1e52eadc26569a1758742016194721b7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:4d826f9533bc2920ffa20c61d840040acace1d0b94c3ba26a98aab41e71a7c20
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:254779dd2711ba240d62835ceff0a75ebf31e1ea7a2a691061a08beea8ac92e2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:215dad822fdb7e31e2f03c1c5c101a1ca2116272bb24117b163933c335569b83
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:8824c49fc62ee179feea88248c242a322ebce40c421ca58aa865c383eed1a040
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:2a8612ab6117194e79cb72c464400b232e6b27b889f49df2aca401d3f95d9655
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:4e6527eb90bae632bd48ff761d0a610983a1b50651fbf6083d490f046fb110b7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:2068c62cff3e2cc5603f522f358958e84fcb210856e77cd22718890a2b393b26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:b53cf8d8ac476947eecc4b92611d89541ed8e19b2baac0a10e650629e08c4d4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:19b0ea3c9b45d36ff71cdb7085de9d9195c87fe7eb38369a5eb1c83ea023db7d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:c931fdf08335092da2b910abfce2f2157c5a7fe2c97e389e2ece1ecf30b2aaa9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:05a0956b717d74b74d07eaf0a680f0bf9ca591707bb7386dba0093bd9bb2310b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:77b7c972d9db82f943992178bad04f34d434bfa6a4535985a5fbb10b161ca719
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:d18c9d4e1ced765e29f15fc9126149e08916c697dc538904f921f1cc89fd24fa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:9cfd0c84ce2a3bae76b59fbb8521d6cbf903d97592a394dd46a7449f45f5a810