Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips

Index digest:

sha256:e1d4a696e212b97c824684fe00e00202c987138a1c20b19b6c5b96dd33bbd1e1

Manifest digest:

sha256:b655dee6f0e6a2077561f7a38d862260efe790b8ad8f341b382e88017d13c397

Size

22.70 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:395d6930d64a6e4896e2417b6ce5c959d81b57a55e061234b2b67eaec48bfc7b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:ed1ea395d251cc3b8246854cbf69667f05b91a578aa70c2915c4e4dc4c9ca30e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-operator@sha256:555cda882e2abdc4dd9f82eadcca5c82384eeeb26b293befd081a8a1062e4414
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:d148ead7f8dc1d3850fa589b800b9686ca61dbceefc4db3274bc974d2f3e6f2a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-operator@sha256:da20f592e77c8c0c04f08909cd66ed115630d05eb9b204996877a78581bcbc35
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:fd408a305e0128122fb9b5ba0beddea2967a63cee825e80b1e6a48fd800ef764
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:34b3bd912d40785a2d899e944e54c88c41b7ae90566826bcb457c0f5d8459d60
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:d38110aae170c459640106da68722d58a531674774e88f231d7edd3eb9229f25
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:c72764b47902f8b4d0a6a8a33e2b8695b79db6381810b19b75f455a2b7514ecb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:8f40828e1627d6d32e61c226dac27d3fa65cc0d654054d0e72eab9198b15c52c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:309b4a6759f5618402e1ba7f813bcdfc8c8da2d32c201084d9dc92a3b613b2d3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:d992711a56cf910e8348a4037bec39f49663d2471468b31f1a4c79e612738fac
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:b2055ada3809dd386203299c82a9857e279df88f2acb8a47622af7b3a7ed851b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:c4ad34b30d4bc7d08e5636860aa3d228f9395b4136d128fb748966e441b931d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:16a6e37780656e3a3093c25a00f784980a2737c28146d253a74a1d43a8de9c0d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:4e01ee0323c2abfdc127187b0b4977de16b6510229d44551e984ecba4e5ddc14
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:21bb20157c2b5691b4845155706547704bf55a7fc4effffbbb38758ac9e5d5e3