dhi.io/dapr-placement
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev
sha256:f32901284f72ece69b552e930db7deed21822cb111edda3cf9ddb03befdaaa80
Manifest digest:sha256:3547ada70ae266270e5879ab9c35fd2484bf4a4d7824fb185011c7703fd448ea
Size
48.65 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-placement:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-placement:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-placement@sha256:98bc8f8e7cc28c885617d683f1ba8d38d4bacac278acce81404c32f6a8c0a40e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-placement@sha256:091a0441c4a5702e1f55762b27cd3e359085a6412d77525c6255c58b22c9d5b9 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-placement@sha256:c99761f41b3639217f36c848c329b16202ebdc27fea9b9024b37df475a16cc1f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-placement@sha256:b9b935d57692c678b89effd1c8dc1d94503e3e28e4bcbe73790103c62154d721 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-placement@sha256:3dd227d7149100b49b83f6aa7dcc8b861995e500f5c5f0749937e347dd189a7a |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-placement@sha256:896a4ca28e0c09fa65138b2a22cb2d3df313faebcf9b5553f72013af4a9707da |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-placement@sha256:4c5a20c68c392e35369fc70f97d0b2d3cf06e34056618f77a206ed32ab1f4ef7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-placement@sha256:ba15e246f70d7d93219742c7824fdd0ad85ed2e347c17d97031130565e391869 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-placement@sha256:171e4e988ff616870a1e5ca36cbd4f207f136067c19ae173f6a8810696243d20 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-placement@sha256:157d095f47d5b9c33c5b4e5566d9e5de4320204f383ec5d1712672f001b60491 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-placement@sha256:89a183665e9e71765b4e442fedd48010813481d5f9d7a073612b2fec7f5e3c60 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-placement@sha256:adf8bd9a03a72dfe68c93cf6970fc63ce6c224435ea6cdfd92c3af1d7828f383 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-placement@sha256:3e2f09b1ec2a23f79b63ba296eb797ceec0df15854e6d2301bb57ccb0523a64f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-placement@sha256:83e9bf5def95050c3470d84c921649d26ac167d7890208b529576e4521411742 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-placement@sha256:4e071714f316971e5caaeb6dff1affebc512c997dd3ea392b38f5f975aafed33 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-placement@sha256:7862f1297ac1c0245488f6367eca31efc4670c638e2a93ec501b2d968d610e2f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-placement@sha256:cdf523bb15d9c7bfc1728aec9b1812f33f1298e3dec460170f8eaf3c5dc17a26 |