Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:27222b14d25f1bdd6c6a4917aac9336f20b212ff5a3d2e6fcc5ea020eaec98c5

Manifest digest:

sha256:cac9700f256e91095ca7c8346a12025fd5ecd7424c765b756dabd6bd86bfe67d

Size

101.01 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:11e8d9b158b7e9989ca713fccf25521f7e7df68fb2879a393d042ae832967d96
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:2916a644f589b2c1618f26124db40e65083cd2c3231ee41dcb0072aa22a81771
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:bf687678a280e6d6a21885bffca366ecd19605f2e681bbcd41a765d9deced66b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:735dbb84b418e2f811d671e9f24bfa39a7ae6643b4eddc318c4d722dd34e783b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:9359b9c735165fa4eb3f13097513464cd26226236687ef052fc9979de21176e9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:21888547a0a78b9e054696a5210df910f6f4acdaafbaff4c8caadb17d6da53de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:d9f4582f08caece63aacd173c8d5cf3eff0b43d6f241f85dadb85593e3f57c73
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:20e5e57fa0a5bc4066f1fba81cf54552054c8ba43f2196b77592ca143fb2a144
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:63d80512afe0ef1553c00f02fe153fd2323509069d77325f9e92e23d8377e3e3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:31da94a9037ceeaf7d9b908b071437ad50576a9c31702f87532ddf28c45cbe29
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:77f93d21b267078229af0c0d1274bcb81f957cb7f322db9eb1550ed301647774
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:7d795a18c8efe45779f953dea39d77ddb8351dcb56cb20131d76eb066504bcca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:1296dd04423da0fa765389434e4385acba78733913e4a3a32c9afd73c5f579a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:8fd75c4e32fcf984d41d1b1f1f56de1b0ef75a3987e8aaac54ad2cb17863494f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:b00db781298afa0c1660381c4b880511b814ff20e4279b0d143f1d61e50bcd26