Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips, 5-debian13-fips, 5-fips, 5.8-debian-fips, 5.8-debian13-fips, 5.8-fips, 5.8.0-debian-fips, 5.8.0-debian13-fips, 5.8.0-fips

Index digest:

sha256:629934cd0d0cd899574d7847ed35100869024dc967c409e3479ca19623ae1c4a

Manifest digest:

sha256:498f27c8ac2571db0d41c04449f7e25079993738346146250461f032edc85e7b

Size

25.34 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:f208462d7aec1af14ff1b2a68a9a644723cd069a271911948f33e6936b8ac749
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:f5a8222d8afec4765b83bc40aed51603afb2748439285dcab531220202b5fd19
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:ad0336549c7a193dd42e9c5cfe71faf8ee1885be6e15b4f2282c8228f36bf68f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:11d24f48656a0fa1aabe03aeed21308ae59b2f1a9c67450d24007b49d9502781
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:0a32901e0ed27abd18ca23e0a0c239417417a468a77fc505a575c105f0ab047d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:bc0e0083f2e181eb6a89fd441a760eb949f609bb45af21da8e5815e0433aa240
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:81fb12b97176ee2f6725c1434cb6844e2c9e650fb0d3f8dc727879fb2b3730c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:8885ebe00e164d63bafe9e9b6353480c59bbc963a579097979adabfc1969567e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:ef0c4857e21442ab0d1274446355b5e41edd2317a73e606a697df4f259c77f12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:58aa5e8a6414a8bae3d5a889208eb6b0337d34e3c5d1230f07b3ab829d152f8a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:2c663b5ec8366cd399fde72eff320583cb46545d5726a7b85d0135085e36d1d1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:d2f1b1349e7d8aa906e9835e7bf36bcf634be1404c619e2af6df1bb885caf680
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:9a7f197059193f99f0d408d7074065b6467e5e7c614d6ccc44fccef7ad5233ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:77411b9e909bfa5ef2a6a9d7e133bd06cc87b2deafd30e22d3c491e7f6e2b9e6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:f3c309d7500faa16ca36596ec14193d2f54c6238ad47cad21269e4d366b22384
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:f103f3a0871ef9456e5428d0fc035405447ad6d1c4f44b3836ab2476b8e77685
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:db38de328f440b1880d71247637ea8eb6e83ca9ce20943c39429a8ca09f27f6b