Sign inSign up
Dapr Operator

dhi.io/dapr-operator

Dapr Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.18, 1.18-debian, 1.18-debian13, 1.18.4, 1.18.4-debian, 1.18.4-debian13

Index digest:

sha256:9c7047ea6b3c9802d48c4032efd1eafb375db35bebf1b83aceba54be8ec98bbc

Manifest digest:

sha256:bc9673c4aaf19c2b619f73471bed44d463217a39015478e8308d42c990ef47f1

Size

14.51 MB

Last pushed

4 hours ago

Vulnerabilities

0
2
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-operator@sha256:f0c8a197f4f92faf85b55d57e2096d6fff9340134f95ded9a827ffaa0c2b7092
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-operator@sha256:b78956511991b9fd2f39f02a14278f7518cb1ec6306f1d34ac2d6aa9f70f079e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-operator@sha256:8a30f7d9e1b42d4b3493729d3bdc8582f55f0177f90efa8fa416aafe4d56fe68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-operator@sha256:c49554426a51630d7cf776bf1c363a8de46b97f0355235a53d8fa1407a675889
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-operator@sha256:b0af0d82ccc396cdfd29426c68f8cd167f8572fd6abbf184c97a38f53001c7cc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-operator@sha256:430ae0054e31603eb9c31b261584019c8e52e3ef1d9418014affd119da93472d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-operator@sha256:97f59c2f6cac0d3b397893a52e6b6e3d0bccf4587afd5f9789226d3f040aa59f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-operator@sha256:e9ee5038d71dac57d6712a182dc1035f53f5eeb4dec6c946c39d130ace2370c7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-operator@sha256:b0fe25f5a2d5bf71d98ecee3ae3fcf1239b6888cfdb78420fbebd11a609e4fc4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-operator@sha256:3c8e3be37fb31959873419fc72d230615d1ad7dd9e9cf28e336723ba20519aa9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-operator@sha256:393810516ecddcec900c3e634cf3b5074eb11da8c1ae5f300ca2c10d83033ca3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-operator@sha256:07630e7b1a8843f3188084f177f2e4ce169217318078c78f641bf75b9df9bf47
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-operator@sha256:2875cc3e2d9b490e6bb1aaa6e2162d990878d09da15c1cfd23061b0d335e51be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-operator@sha256:ecb207fb56d370daf5a28c39fba824429092c79c95df2b5c9bee5f2cb0ebc1ae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-operator@sha256:9b9591817571ac282d6ed5c33e363153207cc2e89e3151f0419ac9a5c4735010