dhi.io/dapr-sentry
1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.4-debian-fips, 1.18.4-debian13-fips, 1.18.4-fips
sha256:eb237142e96cda8221158f0b4338f245c1e996ecc6ef5ff3b9485d1e100ce780
Manifest digest:sha256:c9f8306798407dcc5ce691cdfc62b35e810a59d8f1f3ec0bc107f7a4bb59a7af
Size
22.68 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-sentry:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-sentry:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-sentry@sha256:d4285e94f1b9b520e8dcd19187df603e454f0d4219ea06dab24163d9484f2e36 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-sentry@sha256:cca0aff48127f3a34679adc5238a503ce361c318661c2fbd3c8bfb74889d14fb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-sentry@sha256:7d0ae64b6afa8bee321467954b8c08b08bd22531f0d877a1355126cd19a7ec84 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-sentry@sha256:7aed647d41aa4d1e074f0d49c5b52e120a5a33701c1e1955b0fbe4b96c7ad877 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-sentry@sha256:06b75193330bebe9259018a81f82623a59eaff60cc641817600250021147d7b6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-sentry@sha256:5d8e34a85da52f49f3018cd64c30c24c710a4aaeb988841334f5fcc6bfa54a74 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-sentry@sha256:faf7045b9fb62d68ea6cace4b63ce0ce81daf155bb3f16ea252577570a6bec1e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-sentry@sha256:176d61358b5a455cd861491ffa594a810e4856872feaf3a0c56b6f4bbaf2b520 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-sentry@sha256:9f0a3aa20b97b40c406d2ed8f24d2114abbcb321b2cd1a8ce6135c7a1e970f68 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-sentry@sha256:6e4deac36338564fd6c2a143e9bab09eeaaf9e00fc47f747774613e40bc38f93 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-sentry@sha256:58ef9d349268bcd1388e6e0a40c47ccac36b428691e2d57d02e87b6991717011 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-sentry@sha256:6665cd9e41f70e7dcde9801729993bf5a578e2527725bcc2dacb5550d96b229a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-sentry@sha256:afc2bd4bb6da9df220a4e238855bc7c3fed9ac65fd415793ea15f2dab41283d3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-sentry@sha256:f6dac463c7888569bea79ceeebe06c86ada20e928e921ae291340527c946bff9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-sentry@sha256:a2757f29a6b609bb393c6c16cd6ffe2b283837176c3da33d3b5090fc7129f444 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-sentry@sha256:1f0b30246565e80cec09e98f25419985ca3e88d94a3593d3eaa35e33fd546fa0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-sentry@sha256:79afbd18546a8f5e95f4a06427946506f6236e78c94df92a804f5c1c9b59b7df |