Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:3208627d8be9e305860945761c013af12c1e8cc8aef5815328020e8aaa9af533

Manifest digest:

sha256:90e45cf9bf29512b7826972d23d3dfab9c79d02979fbc2ef83b89f18cbee8ff0

Size

130.25 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:fcb449ac76a54f8d5f5fad66a15e1ad551b5731dfda08d3d05bcedecfc65564e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:91314472eeb59686a5dd63d70211eec3af0b806170b231cc8bb370cd751d5c8a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:3a1b41ce337d3ef579a0e5b4bbd6c97d9696e44c5e0f5c1e86b6202f47491fa5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:1d293745014299d110185537573d06f9764571170ea94c209fd265ac04ea63e9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:3ec2a88c27c78cde9080d752b90f924689495bc52ed1779dbe7c37cadf36e8b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:a88187b17b34de857286ccf74d2e1a4293aaec011e273fb19ba76ddc8a6f2c7e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:78ea4515a97eca0a3bd4592beb70544854044f927b7630f49953a16470739fe8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:d8c347fdcae7fc922d292bf1e0eaba76e28bd4383d2d8756408dc60877448742
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:1ed7480cbbbd496412f76e147962f21bee84e15d6c1ca85ae6fb49e28122a40b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:f2b1279ea21e7f65d9dda353c675351ebd7af235b981e290106459a9112dd346
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:41c73a8d752839cc3f4adf12357d39530de1c0fe2644dab097686c5ef45e7f3b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:5c67e0fff77c4f5fa5d3c7ebece6946cfebf5c02541783449da4c909af913f3c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:deb853603cff32d4e2749473a0dbea7827ce2c74824f41252ce77e8b19f4ce40
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:71000e72a320fa5c86669c8fb4fe3761a65f52ecac5b638c9e0106eee9248224
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:8906ddcd9ac46de7453a74293cef40ab24528aaed4f196857a97006162626fb2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:a76481a3a5e1a12255a566a30e83bd1cab8f0f6f7f5c9f58cc234c9ef04f352e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:187d0abcdcb5cc22141e33ed22f95c1a95a48fb3ffd68aef16a0c561bd29f06a