Sign inSign up
Connaisseur

dhi.io/connaisseur

Connaisseur 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.0-debian-dev, 3.13.0-debian13-dev, 3.13.0-dev

Index digest:

sha256:f41ed4301c28f7e3eea8303a85865ee483109f03e0a013ed50f69b196169188b

Manifest digest:

sha256:6de398da7a05d1d59542e6280a3b2bcc6cad2a50a3533a97b26fc6a7634cf016

Size

69.36 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/connaisseur:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/connaisseur:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/connaisseur@sha256:51ae651e96fbee905f51b00be2b151796db509d11647158572f6a7b76d23601f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/connaisseur@sha256:58e3360c815d9785e276c4e6a116f5ec1aa86f0eae645ba4e530ee417f34b937
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/connaisseur@sha256:a7284dc248857f711b7a966a51e06ba1cd859d4533f1a189fcc6fb401d0c7d10
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/connaisseur@sha256:ee74000b85a9e2041aa7bc615ff25f1ad93c66c453c4cd9c34f2f5ff6249d86c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/connaisseur@sha256:55335668b2e748e0ee784f6d3d4d6ff1aea69c907cc9c30fe31315d30571372a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/connaisseur@sha256:213753ccd9d19feda6bb600c95290af15ce5f6d2cb2b3ec656fed0cf40665b6b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/connaisseur@sha256:b6c7ee090a4ac2f7fa49003742037721d0b102ac4edd32fca431a6d0171db92e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/connaisseur@sha256:70fd1e3b6e6e8d4f128f29bf00e04f11fc3dfec678491cd5ce19dd4f146e1e3f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/connaisseur@sha256:069023ff1c9af1396916149a8887d9e619c116c41cc880eff3f83d2f35760ba8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/connaisseur@sha256:fb2f716fd39dae6ef874c188eb7928c7017c982a24468387d6b593bd9217d45d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/connaisseur@sha256:54c93ce28babcd48027ff7574377eec322371509a4f27b379c6104d4b77ab3c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/connaisseur@sha256:bb40625d910e980f3a7dc339291974f9ffd1cba4021178b88c376f2ac3b1ddae
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/connaisseur@sha256:9768b2f4466266c26efc1d36c08a417a957ae7af194511e778746b869a6ae86a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/connaisseur@sha256:15cfa270963340570e9f41765304c5a59118c2798e3a0bc59db1025cb890b25c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/connaisseur@sha256:77a05e7c3b398123417297a92db03d983609aad822ac3be0c9e9c4efad31e12f