Sign inSign up
DataHub Upgrade

dhi.io/datahub-upgrade

DataHub Upgrade 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.0-debian-dev, 1.7.0-debian13-dev, 1.7.0-dev, 1.7.0.1-debian-dev, 1.7.0.1-debian13-dev, 1.7.0.1-dev

Index digest:

sha256:3e2a5ce8147faed46f8492142f0e87bdee87eebf31cce5aafe814cd18e509903

Manifest digest:

sha256:762f6f50eb5ecefa8ee37bdd6951cdc36ddc142e9c6c6e82d70d799b0e03a03c

Size

793.25 MB

Last pushed

20 hours ago

Vulnerabilities

1
4
8
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-upgrade:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-upgrade:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-upgrade@sha256:88667e1be4e9f2b4febab484aee5b9cef4ab5f137d7ca4400347914373a54903
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-upgrade@sha256:793706c66e2679ed6a72c5023e551398f23afaa36fdc05a9d7199eddbe7b651f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-upgrade@sha256:03217b930fcfb6117634c451e4757c70f751103555eb5a9456dbff272de7f5b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-upgrade@sha256:0738e8c4cb9d61ee014f08e3fa7a0876a856b0e9c1215d4aabefab64935822f6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-upgrade@sha256:64c81a8168e36db1637fe606f0423c78fb32c00b0b6ea73c2de78881437c24b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-upgrade@sha256:d6fc8d6e47c031d3b83e7feb67ebdde31e7a378dc374806bd4c19bea88b0d3ad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-upgrade@sha256:3c6635eea6e7d63a10659960db4187fce9f79db4faaa7c02164eebd6892aef48
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-upgrade@sha256:d81122fd4c36bcbe39373e5538600137593472816783f8fc41d13d771373c3b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-upgrade@sha256:339a3b52e4ccad791d999651e8dd6910a8b3e647ab483fadd1e9af71cd1ffa4c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-upgrade@sha256:db2ac2c1a1d0496bb2291f4c091f722e2e7d9dbfd62e6df139591c5714fa8799
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-upgrade@sha256:db92bb0c4c0acbe20574db36b7409dc1e6c3137d2a6a8dfe27ee825ed5839aa1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-upgrade@sha256:23fbc93a6dc36b7ff88d786fe6a2613c4da49b9b1a13384c3aee3ee4373193ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-upgrade@sha256:bdb07f4941350b90957203736051b0aab8857ecbd659bed684d014892fcea7cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-upgrade@sha256:e12d89f26787ffd24497b6dc8e7f4f634a2ec6b8d6225952983f0f5422f7de02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-upgrade@sha256:5fcad133aa9a0365a086ec1dc5dba0b31c1d31ae4e50aa041244d53ec07e6d0b