dhi.io/couchdb
3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.3-debian-fips, 3.4.3-debian13-fips, 3.4.3-fips
sha256:f13c56952fdd41442cfc4738fe9a01472752ca530379d9a12145cb9112d1b789
Manifest digest:sha256:790427d6fa598ee1f673f037b617cfa1729e24fdf5e4f00ac8217de2940cf6aa
Size
92.20 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/couchdb:3.4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/couchdb:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/couchdb@sha256:7c9947742d4adc8797c053145cdecb7d14fd8787db09363d60d4edf11966a066 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/couchdb@sha256:0b4d941652a557d39aec13eb6263e62fe9fad1e5e78dc070c37b14f4fce7f119 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/couchdb@sha256:c28fa161d4d4528f92ba7ea34cb32adce3f76f9143c80d661ba64dc63ee18faf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/couchdb@sha256:665db31a0faeea5ce3fa5c018bd33a60c37c0594eab535f9dc06c1223c983ee5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/couchdb@sha256:bd4ce0dde1c2d9f9daee0bb3e50d71987c85e63b1bf970d72298a5b67872b32b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/couchdb@sha256:d1edb67a5a7b4e188d78ff197f66337b9149bc672d750b043ade80d0848d1e85 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/couchdb@sha256:5fb06f04869b40f95a6ace9f6631636939f7ac3f686c09c6b3b293ab8e1c6f0f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/couchdb@sha256:b9c74e34dcc56719d09ecdea3b68119704d3fa3af354cbd89fec789227d1309a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/couchdb@sha256:f6df74f2163da64f7ad3291cc87f6277630262fba4a437a0ed1b0c7deb69cf76 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/couchdb@sha256:85f0e0931fc6849876f513ca9eb9aa24cfc9d20d8047b280aeef765d27d409ce |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/couchdb@sha256:ecb6ec37919e5e2c67e1d991f97451da7d3230baf3256b31fa1b4032a80c1f19 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/couchdb@sha256:a78dd36203a106b37d1b6ef1947945ce4fb92218f0decaf61c928a8f0c915180 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/couchdb@sha256:a378843a5bb9de14eaa5804a57c2d974e8229712cf4732011f4efffa7d052a4c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/couchdb@sha256:1bc452e99d90b0ea95d0762b191a6ee615779bcd35e441794918312d5648c911 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/couchdb@sha256:49bf7b4544449a833091485dd1aaa9a1fe13e10005ac7d763d48fef63f9aa1e8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/couchdb@sha256:a420b00d33f7fdeaa50c09546862d5fb4f93fa4d094abcc0516b61abe7f55d39 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/couchdb@sha256:0aa7d6d4b9494ea810ec5cb83a0f4ddb7584b4399ddc0e3f855b64de8d062831 |