Sign inSign up
Connaisseur

dhi.io/connaisseur

Connaisseur 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.12, 3.12-debian, 3.12-debian13, 3.12.0, 3.12.0-debian, 3.12.0-debian13

Index digest:

sha256:e5a6ffec760793db2798fdb130d0617d5b2c10a2ac5f2cdf71af5eabb434ad0c

Manifest digest:

sha256:247caccdd4559d58a3d70dbfd35474982ee63aa96590def3fc92f17f40177c7e

Size

22.61 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/connaisseur:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/connaisseur:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/connaisseur@sha256:855b05f9922c67239d0db39aa069b992deb94a8531a6f9357f0afce34c21dd53
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/connaisseur@sha256:8f3bcc3ed635013c8bea6ca16e424f69d70fb0cf9c3aa7d6161a7f7a03dc5fb2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/connaisseur@sha256:1d6653a6b04665650ccf38d3c8c922a1d7c72dd2170a95f95f558a2764a3a193
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/connaisseur@sha256:b3f768d9c51e6e806e66f84a348e037f315433ecb81d8a62663a8216b928753f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/connaisseur@sha256:8f515cf77ca4b5baf03d1fcc1c4122c149685d02b76da626209197da30c43b34
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/connaisseur@sha256:a8c01998d46e7020bd5b634313f592342d5e2e5792da8b570f5664c5b12c6d5d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/connaisseur@sha256:456c247f0591a532700f6066a1fe51f029a8ea6af252e1da60ec6e46a93ffc13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/connaisseur@sha256:99ea59235ad738356f478a799d59ad6d487c695d992808b731964ce1c7157f62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/connaisseur@sha256:d25dabfd584edfc42d18a1c6356d541b39875862dc1cc49d376b57e464e60984
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/connaisseur@sha256:c499b22fd85754317c78efdd1a768ff1f08636465414a405971e75901d4b559b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/connaisseur@sha256:843a309306dfaf732ea491bc4ff86ca0aed5a84975487b5d829b3069a9e08cf1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/connaisseur@sha256:c277a5404d9c8d1ec4e577f2d637464ed65a5a4bcc6da0e2ffc607d680ebf605
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/connaisseur@sha256:d276ef6ed50db4b8f7067335b5e6dc9d016366a0b922358ad7fa47fbf508557b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/connaisseur@sha256:8b5538baf90780757d5b11124479813b3d1bb1abc449c5b576e5fd37af3b770f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/connaisseur@sha256:935bb940f9732774eacf9273a38ac18e91efa19017d5b90ab12bdb85f0d0828e