dhi.io/dapr-injector
1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.4-debian-dev, 1.18.4-debian13-dev, 1.18.4-dev
sha256:f82c671b678bd57c689f5bd2dc2da32c98f5ec9984bfe161023c3d6b7474443a
Manifest digest:sha256:90bd339b7e245f44ed3da16b48d8234116185622795ca0e91c027780ea3856a4
Size
50.41 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-injector:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-injector:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-injector@sha256:4b7691a9896eb73a506b0c31a28197d5d6bcd8fbbcde17c230117d5a9b24d6e6 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-injector@sha256:06bf6b71aa40a47211f18511ab97585cf407f2f0fb578f5d929df00a003d2592 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-injector@sha256:2f917b4a4b25382f095b1b19c2a013b767b41299935fcb35567f4d6e04fe7b31 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-injector@sha256:fb0616d1725e498059620c176fc06bb3aa95ed11f983af171f188b57220f5962 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-injector@sha256:a0dafdd55ba7f162aaca45e3f489eb59dddf8e31f3426ec1af9dc9f023216724 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-injector@sha256:1dade2ddee9f6c09e845c6c2521a5ff3dedb321e01ea8f9a235c8bed2f39e8f3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-injector@sha256:bb4723c379b1e4ff8a60971f7bdd8cf527e51b4684ec76bbfb6a8df2bf36d956 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-injector@sha256:b56ba4451f957d1883213d20f6ee1213df95ecfcd782077d75b4106cbd6fda91 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-injector@sha256:c51662cfd54bd943eea9b670ad27bb1ded9cfaa3a304029acb30cd22fbb76fe0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-injector@sha256:9ba9ff5fae51556a10345b5ebb7709a9f531276a86f1849f3383d1f22dc170fe |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-injector@sha256:a4fc4434d28d3f582c56e57e7dfeff3b2feba0edb44d3ff03cda97788f02b858 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-injector@sha256:b2ee66ea5b07df1c4dc372956953fcd0ab26277944cbf18784c09be6c563b9a8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-injector@sha256:764cfedda377b675d3b73c038360351b3303bb1627c05cbcab552853146c4b09 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-injector@sha256:aea53d18f0b5073f378370baf74660a92f15ae3316581390329448af42c46c09 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-injector@sha256:ada99fbbea2ee4e70e2e5725583eeb86a466142ed7bf8154473ffed1cfbadba9 |