Sign inSign up
Dapr Sentry

dhi.io/dapr-sentry

Dapr Sentry 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips

Index digest:

sha256:eb237142e96cda8221158f0b4338f245c1e996ecc6ef5ff3b9485d1e100ce780

Manifest digest:

sha256:c9f8306798407dcc5ce691cdfc62b35e810a59d8f1f3ec0bc107f7a4bb59a7af

Size

22.68 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-sentry:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-sentry:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-sentry@sha256:d4285e94f1b9b520e8dcd19187df603e454f0d4219ea06dab24163d9484f2e36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-sentry@sha256:cca0aff48127f3a34679adc5238a503ce361c318661c2fbd3c8bfb74889d14fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-sentry@sha256:7d0ae64b6afa8bee321467954b8c08b08bd22531f0d877a1355126cd19a7ec84
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-sentry@sha256:7aed647d41aa4d1e074f0d49c5b52e120a5a33701c1e1955b0fbe4b96c7ad877
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-sentry@sha256:06b75193330bebe9259018a81f82623a59eaff60cc641817600250021147d7b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-sentry@sha256:5d8e34a85da52f49f3018cd64c30c24c710a4aaeb988841334f5fcc6bfa54a74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-sentry@sha256:faf7045b9fb62d68ea6cace4b63ce0ce81daf155bb3f16ea252577570a6bec1e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-sentry@sha256:176d61358b5a455cd861491ffa594a810e4856872feaf3a0c56b6f4bbaf2b520
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-sentry@sha256:9f0a3aa20b97b40c406d2ed8f24d2114abbcb321b2cd1a8ce6135c7a1e970f68
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-sentry@sha256:6e4deac36338564fd6c2a143e9bab09eeaaf9e00fc47f747774613e40bc38f93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-sentry@sha256:58ef9d349268bcd1388e6e0a40c47ccac36b428691e2d57d02e87b6991717011
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-sentry@sha256:6665cd9e41f70e7dcde9801729993bf5a578e2527725bcc2dacb5550d96b229a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-sentry@sha256:afc2bd4bb6da9df220a4e238855bc7c3fed9ac65fd415793ea15f2dab41283d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-sentry@sha256:f6dac463c7888569bea79ceeebe06c86ada20e928e921ae291340527c946bff9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-sentry@sha256:a2757f29a6b609bb393c6c16cd6ffe2b283837176c3da33d3b5090fc7129f444
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-sentry@sha256:1f0b30246565e80cec09e98f25419985ca3e88d94a3593d3eaa35e33fd546fa0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-sentry@sha256:79afbd18546a8f5e95f4a06427946506f6236e78c94df92a804f5c1c9b59b7df