dhi.io/couchdb
3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev
sha256:27222b14d25f1bdd6c6a4917aac9336f20b212ff5a3d2e6fcc5ea020eaec98c5
Manifest digest:sha256:cac9700f256e91095ca7c8346a12025fd5ecd7424c765b756dabd6bd86bfe67d
Size
101.01 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3.4-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:11e8d9b158b7e9989ca713fccf25521f7e7df68fb2879a393d042ae832967d96 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:2916a644f589b2c1618f26124db40e65083cd2c3231ee41dcb0072aa22a81771 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:bf687678a280e6d6a21885bffca366ecd19605f2e681bbcd41a765d9deced66b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:735dbb84b418e2f811d671e9f24bfa39a7ae6643b4eddc318c4d722dd34e783b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:9359b9c735165fa4eb3f13097513464cd26226236687ef052fc9979de21176e9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:21888547a0a78b9e054696a5210df910f6f4acdaafbaff4c8caadb17d6da53de |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:d9f4582f08caece63aacd173c8d5cf3eff0b43d6f241f85dadb85593e3f57c73 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:20e5e57fa0a5bc4066f1fba81cf54552054c8ba43f2196b77592ca143fb2a144 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:63d80512afe0ef1553c00f02fe153fd2323509069d77325f9e92e23d8377e3e3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:31da94a9037ceeaf7d9b908b071437ad50576a9c31702f87532ddf28c45cbe29 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:77f93d21b267078229af0c0d1274bcb81f957cb7f322db9eb1550ed301647774 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:7d795a18c8efe45779f953dea39d77ddb8351dcb56cb20131d76eb066504bcca |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:1296dd04423da0fa765389434e4385acba78733913e4a3a32c9afd73c5f579a5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:8fd75c4e32fcf984d41d1b1f1f56de1b0ef75a3987e8aaac54ad2cb17863494f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:b00db781298afa0c1660381c4b880511b814ff20e4279b0d143f1d61e50bcd26 |