Sign inSign up
DataHub Ingestion

dhi.io/datahub-ingestion

DataHub Ingestion 1.7.x (locked)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.11-debian-locked, 1.7.0.11-debian13-locked, 1.7.0.11-locked

Index digest:

sha256:9690df5919f0f96c5aac8378a3804ab8d2703923732772daf5e71d9ada510f39

Manifest digest:

sha256:ac7abbbf0317f2bdc69511ee81957f1daf78e3a7d985d5e5fec2ab799121ba49

Size

128.78 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-ingestion:1-debian-locked

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-ingestion:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-ingestion@sha256:affea79d798808ce82455102e6f210de26b1884b7e5dbd9bb6b0a8c2075d2d98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-ingestion@sha256:2aab784e3bedba98bcc95ba411333c817e2552376cd3d919e31e97c7dc318e76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-ingestion@sha256:eeb1c685e9593898b5325c3eea84802de1e64368931b35fc231e16a46ab99c03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-ingestion@sha256:363272e58ba73cbad5fc67406278206f0d7a7eb7b1ce80e1ce58ad631af04de1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-ingestion@sha256:ff3e3055bae1931108fcc5e0189cd0e1eba273b3b682e3e52b0ab47c11165ef9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-ingestion@sha256:d9f75a92d04f5453178be9e77f97fa229a6c008e49aa493739b0daebc8936ed4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-ingestion@sha256:be509005576c1648dfa1e3df8cdd0f50fc39dda2f4fbc8fcb6277cb1ae49a23e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-ingestion@sha256:d201d115110fb5654b8c6e155ec1a1519ec41300ebc09e2a5937dafccc3b4d31
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-ingestion@sha256:1be73b46c42276163c3e976b86581bd797bebb6b3e182a3cbf60755554c934ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-ingestion@sha256:6fcde60245319db65ea262b4ddef7f95e6ab5075c4f12ca5af9d64700febd63c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-ingestion@sha256:1042732a23ac26d2f2159c831576a7f9b1e48f14b355517c2f2beeda36159bb2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-ingestion@sha256:0d68f80404f780c5ab634befa7d59c1c5d11d556b383d0436909dbab9a8eec0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-ingestion@sha256:f050ca62dde4fcdac7ce480485c108b81c5cb769b87a9d44905743bf2058287b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-ingestion@sha256:ad343ff4c3b116dcbbd79b6c6d421ae23c31259f92ab550e40e927ece49a4ac8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-ingestion@sha256:0f3ca811951428bf876973475c067725b76bc563975d14c09454a32e54173d8e