Sign inSign up
Dapr Placement Service

dhi.io/dapr-placement

Dapr Placement 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:f32901284f72ece69b552e930db7deed21822cb111edda3cf9ddb03befdaaa80

Manifest digest:

sha256:3547ada70ae266270e5879ab9c35fd2484bf4a4d7824fb185011c7703fd448ea

Size

48.65 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-placement:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-placement:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-placement@sha256:98bc8f8e7cc28c885617d683f1ba8d38d4bacac278acce81404c32f6a8c0a40e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-placement@sha256:091a0441c4a5702e1f55762b27cd3e359085a6412d77525c6255c58b22c9d5b9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-placement@sha256:c99761f41b3639217f36c848c329b16202ebdc27fea9b9024b37df475a16cc1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-placement@sha256:b9b935d57692c678b89effd1c8dc1d94503e3e28e4bcbe73790103c62154d721
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-placement@sha256:3dd227d7149100b49b83f6aa7dcc8b861995e500f5c5f0749937e347dd189a7a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-placement@sha256:896a4ca28e0c09fa65138b2a22cb2d3df313faebcf9b5553f72013af4a9707da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-placement@sha256:4c5a20c68c392e35369fc70f97d0b2d3cf06e34056618f77a206ed32ab1f4ef7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-placement@sha256:ba15e246f70d7d93219742c7824fdd0ad85ed2e347c17d97031130565e391869
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-placement@sha256:171e4e988ff616870a1e5ca36cbd4f207f136067c19ae173f6a8810696243d20
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-placement@sha256:157d095f47d5b9c33c5b4e5566d9e5de4320204f383ec5d1712672f001b60491
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-placement@sha256:89a183665e9e71765b4e442fedd48010813481d5f9d7a073612b2fec7f5e3c60
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-placement@sha256:adf8bd9a03a72dfe68c93cf6970fc63ce6c224435ea6cdfd92c3af1d7828f383
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-placement@sha256:3e2f09b1ec2a23f79b63ba296eb797ceec0df15854e6d2301bb57ccb0523a64f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-placement@sha256:83e9bf5def95050c3470d84c921649d26ac167d7890208b529576e4521411742
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-placement@sha256:4e071714f316971e5caaeb6dff1affebc512c997dd3ea392b38f5f975aafed33
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-placement@sha256:7862f1297ac1c0245488f6367eca31efc4670c638e2a93ec501b2d968d610e2f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-placement@sha256:cdf523bb15d9c7bfc1728aec9b1812f33f1298e3dec460170f8eaf3c5dc17a26