Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:a751e049ca4a2a95a01538573e8d64a7f623a42a435428fe2e97f5225fd9401e

Manifest digest:

sha256:1986af11268c44e56ba9b9ee34c30f5b9030ef21763ddd8a291c6b8e5d5e5be9

Size

129.89 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:5f20452eb3cbab5523438804d173a36e0feeb1a71e32c35e16e811debd4be60a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:d9aac7123221ee41a3d727a6456f3c34cda7898303fe0494bf785503e12b0a5a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:b6ff6d2e04a330d1c1b7093c37a110639c5c607ffe2f83f61251dc4ca3aaee2c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:d8687121faa69388162760e4ee3680804292b3ba1763ac67d5dc1f824fd6b311
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:272ca69478d14da1fa9423890e27a115c3074ef92a1a831c33d1ae32878ac4d9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:03586457808db5e37e5244ea11cce3eb443044da95362eb1318a50ee9220765c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:f1aadbf3a62f8cf1bce4e2e35e699a99d37515ddadf5c04af06ce62e7aabbad2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:8bec8e263cceea78c3ec8665d82b9cb78d5d14dbd6d7be7768f3d43cd374ff59
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:67557847f3fed2214be537ff67c5e8770396c45c76f2cf9c47569ec2eef3e014
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:6ea3bad40b3cfa619293d719564f1beea6823e23c19be67b3795bb295727d0dc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:8ba4087e3b015c4e38fe1ccbce3fe19342d64d494044e4aff961202023cfa027
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:2f6d473de089077373aaaf4ba33af85439a5beb357e75e3cfde4513af7cdd28c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:f13522a03b6e224320ab3b9f1e7c534c0c1ac5bb65e09f68fd4ce07cac533dd1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:fb9f06609d23271a4dbf61e69cf01a76b105fed4cb1f1971865dd5b17a8f97b2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:803a664675b46313aa47b135fb0dbfbd37ece9b2d3230177588db1efae7881dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:5a13b6b2c97eeb77cc40632eb60a008e65daa5c4a772d91f4d00710a4e0b27e4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:41049c9e31235842dc260e5a9bf9972bd3e1be0e6334a2d7ac8be13737f0b40f