dhi.io/datahub-ingestion
1-debian-locked, 1-debian13-locked, 1-locked, 1.7-debian-locked, 1.7-debian13-locked, 1.7-locked, 1.7.0-debian-locked, 1.7.0-debian13-locked, 1.7.0-locked, 1.7.0.11-debian-locked, 1.7.0.11-debian13-locked, 1.7.0.11-locked
sha256:9690df5919f0f96c5aac8378a3804ab8d2703923732772daf5e71d9ada510f39
Manifest digest:sha256:ac7abbbf0317f2bdc69511ee81957f1daf78e3a7d985d5e5fec2ab799121ba49
Size
128.78 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/datahub-ingestion:1-debian-locked2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/datahub-ingestion:1-debian-locked --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/datahub-ingestion@sha256:affea79d798808ce82455102e6f210de26b1884b7e5dbd9bb6b0a8c2075d2d98 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/datahub-ingestion@sha256:2aab784e3bedba98bcc95ba411333c817e2552376cd3d919e31e97c7dc318e76 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/datahub-ingestion@sha256:eeb1c685e9593898b5325c3eea84802de1e64368931b35fc231e16a46ab99c03 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/datahub-ingestion@sha256:363272e58ba73cbad5fc67406278206f0d7a7eb7b1ce80e1ce58ad631af04de1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/datahub-ingestion@sha256:ff3e3055bae1931108fcc5e0189cd0e1eba273b3b682e3e52b0ab47c11165ef9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/datahub-ingestion@sha256:d9f75a92d04f5453178be9e77f97fa229a6c008e49aa493739b0daebc8936ed4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/datahub-ingestion@sha256:be509005576c1648dfa1e3df8cdd0f50fc39dda2f4fbc8fcb6277cb1ae49a23e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/datahub-ingestion@sha256:d201d115110fb5654b8c6e155ec1a1519ec41300ebc09e2a5937dafccc3b4d31 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/datahub-ingestion@sha256:1be73b46c42276163c3e976b86581bd797bebb6b3e182a3cbf60755554c934ca |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/datahub-ingestion@sha256:6fcde60245319db65ea262b4ddef7f95e6ab5075c4f12ca5af9d64700febd63c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/datahub-ingestion@sha256:1042732a23ac26d2f2159c831576a7f9b1e48f14b355517c2f2beeda36159bb2 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/datahub-ingestion@sha256:0d68f80404f780c5ab634befa7d59c1c5d11d556b383d0436909dbab9a8eec0b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/datahub-ingestion@sha256:f050ca62dde4fcdac7ce480485c108b81c5cb769b87a9d44905743bf2058287b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/datahub-ingestion@sha256:ad343ff4c3b116dcbbd79b6c6d421ae23c31259f92ab550e40e927ece49a4ac8 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/datahub-ingestion@sha256:0f3ca811951428bf876973475c067725b76bc563975d14c09454a32e54173d8e |