Sign inSign up
ChartMuseum

dhi.io/chartmuseum

ChartMuseum 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.16-alpine-fips-dev, 0.16-alpine3.24-fips-dev, 0.16.6-alpine-fips-dev, 0.16.6-alpine3.24-fips-dev

Index digest:

sha256:91b6efb5c017d85921874e49cafb42f0f284b176f5a00cd424e6ecc51c56630b

Manifest digest:

sha256:3ca4fcbe582995dcceba4e407cce2c615d58b900631168799a20516244e9a57d

Size

23.66 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/chartmuseum:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/chartmuseum:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/chartmuseum@sha256:bcd8574dc79c9becad23e307774d4cae03a828938bbee80a57c63d05443066d5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/chartmuseum@sha256:e8103143c34338944e94af27e66561bf624f2bd9cef3112d3aaa3bd318419ca1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/chartmuseum@sha256:3863e6ba74dbb6c0e1281badfc8a1c9b6f925e82bee4cf6da35db9122692ba6e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/chartmuseum@sha256:5e71f6c879624349ea74ce8ecb50c5ee201dec9a7cdc77d43fbb62fafe67e48b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/chartmuseum@sha256:1985e13ef0b756914a63a72a182434170139dbd610c8f1d0b8dd01267fb2721f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/chartmuseum@sha256:74d0f5fd46f139d6a9898e16559a1396b59c126f13527154e324101ed5aa2d09
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/chartmuseum@sha256:0fc47a84f29de8d63ad70dabcf819506907f09864bf7a52a167d3162f249a665
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/chartmuseum@sha256:f062153da07df65ce70612e1a2e73e5b9990855e279ec660916698db76f7b269
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/chartmuseum@sha256:9c0f667b84c3a6bb601ec239d65626b9bc7bb5ccf6226644b90e5445dc75852a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/chartmuseum@sha256:149667540f18c8c08ba25affbee26c544120287dbcecd9e2cdaee39654bf4143
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/chartmuseum@sha256:777ce86be38e6692d56c54450552e78041fc7205082cd9dffc08287cff615031
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/chartmuseum@sha256:4eee85cdc2a3f20e664862078034f3766ddd3d503779aa297099d15115dfa36b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/chartmuseum@sha256:87a49ee8b78371b9d2e4ae2d642b99e7ae176af965b0d5a4fbacaadc4f9ab620
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/chartmuseum@sha256:23481c39ab8165ef320a9e357e622f7eee47f99a61bf2d27b02ae83616372168
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/chartmuseum@sha256:ff344bcd49c40fc4b832b6f996ea00084a8cf20b5f442625e584f94092d0c638
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/chartmuseum@sha256:906f38985f22cbe1da9afb218959c7083bc4bf73aa01f3eabca27b2df7d99c08
SPDX SBOMhttps://spdx.dev/Documentdhi.io/chartmuseum@sha256:0ac162dedef79361022c8db2d309d55cc19847af12edf77d9bc9abce221c0f8a