dhi.io/datahub-actions
1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.1-debian-locked, 1.7.0.1-debian13-locked, 1.7.0.1-locked
sha256:35c810911846f86c579f95357e0ee59e47367cd59b473442f22e04e1368189f8
Manifest digest:sha256:e1afea9faba99b1b3b3128ac40ce11668bb5826070c44c2c1a148d2c5d16c5d9
Size
79.39 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-actions:1-debian-locked2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-actions:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-actions@sha256:3e545a112bb99d49da41e206828b332b285d515ebafa40b75cd457464eeb1056 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-actions@sha256:79add55f40923d2e4c1d1a40e89337c4bf2eb359f75cc8bae35f81b5488dabd6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-actions@sha256:5906004554c4daf399b2ff45e6f70ec9425e6317796d10f338293ecd63915641 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-actions@sha256:767a778a1c953dc11b6c52a7e1082738a71a96a44ffe279b5f264d8c08554935 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-actions@sha256:4a188491829ca88fcf4826c2f086afcc4b47e4048ae007ab08aff72c5d02f7fc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-actions@sha256:11b2822e5eeb45475650a30487114a6b4e6ae084c824038263125c75f4683ca7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-actions@sha256:c4a40ed42869e01367c51682bbe3ede5e4b0c0085ddc6973df5be17caa04c1de |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-actions@sha256:6aae2354cc23a84c383a0c104bb3cb62e71a6bbbc5c26e1a0c136726352b763b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-actions@sha256:c35090f70186202ef30125b58cbe7d0d92f8114cf3d9d15dfa0be1d117fc89b3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-actions@sha256:1df5a4504023208332d083fe315a9fdbb55644a3544aad5cfc41fb9536570f5d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-actions@sha256:a213e3a89dc1126c340de7dbec644c23dab26e1795d86ed7a1170c1a65673431 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-actions@sha256:cbf471986d0e948eebd9027166b558bdf39f56db8d654af3c0288f73b7c03246 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-actions@sha256:9201b95435f2df9575f5408cc1cc69464b228906dcbcebdd9f2aed6d83a6a4c3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-actions@sha256:44dac62ce84679349e28134747d7577d2bd137189a3f14cb13df9e5e84d151e3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-actions@sha256:6d0e82040a90c18be32b8b638822c3e8886deb02df765bf97c52de04c3c55487 |