Sign inSign up
DataHub Ingestion

dhi.io/datahub-ingestion

DataHub Ingestion 1.7.x (locked, dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked-dev, 1-debian13-locked-dev, 1-locked-dev, 1.7-debian-locked-dev, 1.7-debian13-locked-dev, 1.7-locked-dev, 1.7.0-debian-locked-dev, 1.7.0-debian13-locked-dev, 1.7.0-locked-dev, 1.7.0.10-debian-locked-dev, 1.7.0.10-debian13-locked-dev, 1.7.0.10-locked-dev

Index digest:

sha256:63d5eec12ab01b0f7d84aafc5ac1e85d43d60c3cc48b971724ff778a6ae291ea

Manifest digest:

sha256:98e1c5b5dbac321f1dc2fca0551c0e0a5be7ecb1980f8bc1276ba603fb405f2a

Size

141.27 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
7
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-ingestion:1-debian-locked-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-ingestion:1-debian-locked-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-ingestion@sha256:03a4c9dbce5a9f221cab70218f31c9ce906fa3f92c910ee63642b985dc48ae36
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-ingestion@sha256:b4b0fc0397c5b66d65f7b4c4db059854d15edf3e4b63d2d92851254c56cad463
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-ingestion@sha256:72af9565535d3a0da1de068276d303359ee54dbfbd158030d0dc94b4add01ba3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-ingestion@sha256:fec48933f035f7e306b72a787860dcd9698727e9280b850df02b428c538f5ad4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-ingestion@sha256:3158efafa1865bf8958c3ad7a277db6efd2046ac659032e68088dc4719030bb8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-ingestion@sha256:e6251a2c61c698464ede790f53538f92528492f54ebafb544c5b634a7ba63cf1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-ingestion@sha256:ab3eaafd3a9e6d3062f1284f809bb39fbb86d45b334e27f98a371e8870e72dbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-ingestion@sha256:b234e342b2b2776bbcb3026aa15236aedabc6aee049eff1f8f0bbcd51a4197ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-ingestion@sha256:ede4e454cc6c40a68c8d8e9f1c1edd2e3874b15a2cf792a6f0bfdb8e700e6cf9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-ingestion@sha256:a0b6f5b81b0034ff9ccf7b9e0a030ba257820d5d41ae0e24237fce8c57a020fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-ingestion@sha256:17b31a1d62c98e6bf69ad150c083ad0443c09bcb163c6f98b6b40419a83a9424
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-ingestion@sha256:8df9302ae4d55ae51783ca2c2a95f692d1d5ccd6177f41ff2340f6ef9a98d6f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-ingestion@sha256:258e34bd860677bd83e7a788807144a52e03f71d514f2743ab5f69dd815521de
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-ingestion@sha256:656d91a935498bab040eec97fd0266761fbbffb2b5f855e964ae4ab29d123351
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-ingestion@sha256:f67f30ae355200ae849ac3ea2e0734682607389cd88dabafa61eceff2fbb319c