Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (locked)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.1-debian-locked, 1.7.0.1-debian13-locked, 1.7.0.1-locked

Index digest:

sha256:233fd2b778284abcac316718d5772352f607f6bd43e826adb4600cb8b1170552

Manifest digest:

sha256:d0a24edad19f470829ccbf185ba8a9509195c08cb2d4f54fc65e2cb0cd4986a4

Size

79.45 MB

Last pushed

1 day ago

Vulnerabilities

0
0
5
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-locked

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:53307385f46091cf9cca1a81d23b6f92d15de7577c201d86b961e1a5ff46b75b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:b80a4d11e875c0eca11becc6d3f1f088ba7eec11da02f358f57146c07ee19c63
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:ac97d5770eb439515d047d6d253e95c898c43216554b352cfb9b9195e3c51294
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:693c38fd4ac0ec8fb2c0bb0d7935f1192ae0d8db2f9795fd6bd579245e0570c1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:95e12e971b5cd6b64a6f65e7a8eb318ca3e2e5634ccd920756b5e0154a81eac7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:eed6c78749eaeda62183a19f456b73e9ca171bc1dca81540be12e54ea2f86b12
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:9d0e38489d7a2d6886f1f8034f6423d1404161a65973e2b23c5e775c49c7a4ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:5edd79b1b594b500bfe0c668f7af1524c6fe7415fe9e31d3803e6a0af9577c3d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:b42b3195b97b7034a042fc5eb99ed6f3bd5e65d25476326692b8ed0328594419
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:55f9384ccf1af6a9357cc4d520b00df16783e4432093a77869943bb4105febfa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:d81c3986c79aa508bd8a7d5f0519c16486fcd57bf8a44cc365242816b3cc0941
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:17137101afb5b495b1702af58cafa2bba417a4940cdf7b1f56e5613b27f0d135
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:373554c7fe2b21ee942d2f7eb2ba22ad7aa900f92ca31f28a106fab4ed6391bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:e99644f87161b1ee6f956d82e114d6af4b8096e39b256c4711a5cfff4d932017
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:8d3556153615da66d809835c41be89831b93cca1a3e2fb332bf2aceade5eb09e