Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev

Index digest:

sha256:ecec2a0d6748362adc20806b8487b49fb47b4af2086b70afecb7c26054eb9245

Manifest digest:

sha256:4f5f304804b3e1e9ac1e13e22055aafd19bc47fb731f3c47ad7caa4d98040083

Size

37.79 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:2d6a377d3201d3ba7b3906e975d9db815f984c52f0d93f50af54b04e5914e2e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:b840268e07017fb8b2482680a78ff814155f0955b01f772c5a6d59ef5ca56db2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:fd5e3748e12b47c65c604701c6b2932e0d1169b4392ee7518f629fb8baafb8e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:8b7444c63e36c1fb7e0474730e41420132c836f6275a9ebc008092ad47e31572
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:56912a175583e043fd5afe83e22363fd42dac92bf0ad024809c36caf89c40c02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:c7c946d2138d57a2bc1dd63384b698340e7c0e60cc6a5b1289b3c5a0e0532955
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:67d84551b6955f0c4337da708dee076e1efdfea617af43dab770d05d7b12ee34
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:c41deadf6615183ba342a2f4311a17ff157d9da6e73d95c035f1a25f0f482424
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:a53ffeaec6d24fdf33b376f313fbb263a1a0d6475b145459f5cf29b267863fe0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:2ca61b6016867683f9a77042dec077f575374eb145e2fc0a95cb9e824d66368e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:e8d9c022c099d713910cac01cf8e719ea14bb926abcfd2f4a75855fd0fe5fc0b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:eea7b728928f16a3b0b18747980fe6e6313ce0caef1095c9e3f86d09c49226ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:2bab5ec5f7b899dc4071ea9f7344cc01b9d2673af558773e688d3fddb5d6a03d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:8e4ed158bc5ee7191d64692ba62314c42f66654f39185cdf5d2fd98331eccb31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:ebee6643f84f8190a01041a85a083c0388ce64cd6f9768a33cea9b0af4d8b55c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:0e0f4e6701bcf81504577bcc40da503e1e28aad1200f4ed68f0a0030a75903a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:f358ab034ab374885af47f7e72def024dd216f559325c7c4f2f9d657f0f70267