Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.19-debian-fips, 2.19-debian13-fips, 2.19-fips, 2.19.0-debian-fips, 2.19.0-debian13-fips, 2.19.0-fips

Index digest:

sha256:31cebccc7b177876ac26538637a3c919ee75acdfa08ef2cfbef6b60dc691a2f8

Manifest digest:

sha256:c8170025a881f74e08282218636e7a3df6cdeae7d8cdb6d4977cde297db551ef

Size

20.16 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:474e4c9b59651b160e1f33e0bf2501f6e0687f19bcb9516cb0226e559c1c85de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:afaa4ffd119ffcb5a49d9678b762bd55619ca05c53cbf30d7b9374e3f7d26b9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:a1218faf0077234be4b75c3f921c01940507012dadadbcb73ea971be0c66c6fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:6f5dadb6be17842bb6330968006b17b0e126528849ccac82fcf973253b5cd607
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:efeccbe2a1aafcf63c8a0c0f1eee3526792948e7abb292e218bdc389fa0aa420
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:eea7afec68e1814131341c70b47ec3ba6c6253806e98fe8bc6711ca2c508e2d8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:a6587ad6e4211a3c9aa801fab0b5a0fbe0182475d57297d0867f0b6620b24806
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:346dbd61b823e5c46a229cf8797e4e0067c13fb10ee59457115718f384a8fbe3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:c1edcc443e34a13abccf022d88fbdc7e8542529a1c5c4199776d772fb4713537
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:cac981dd32ef9a0c465376f0552df3d86b1cd3eba139e701bc4c2608abe52011
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:9e9d6c4d2e3b34d5c24137ea1a1afb083e2a2b2a34b1922254f362d5006478de
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:4e4c3d05057dc1bac5e5a650eb60e827e45fbbe9b1647136243f697bd394186a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:b692e4b733f9bca14522744c7c68fcc7930c9eded65bcd49872facc753906508
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:4087313c7b022066c46b2387e7a1e8c68f2a3608c314f3d50f701ae7e81a549e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:eb8ea8dbfda71b5f0d0ce6385965e633ec0dc9d58eb8a07b24c09dfe1fe16710
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:9cd7ea51627f488cd947cea2d7903e3c3bcbc812c6a092e83d911e4b9a1ba712
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:22ee76e59724db0f3e277e73edf40619d279436941e1c5c3d5a425d6bae60ddd