Sign inSign up
Falco

dhi.io/falco

Falco 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.45-debian-fips, 0.45-debian13-fips, 0.45-fips, 0.45.0-debian-fips, 0.45.0-debian13-fips, 0.45.0-fips

Index digest:

sha256:35832a3688968fbc28568679af916267c4a8312006b0c05f99bf52e99b687425

Manifest digest:

sha256:7dfb2eba5ee788fa1be14a1c9fba8db1685a77b2e934da4b3eae74ec6749dc2f

Size

24.09 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/falco:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/falco:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/falco@sha256:7fbe1ec9854b0ed2303b3ddb9340f1cc8ba497a881c7aad57e04458872a353ec
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/falco@sha256:99e8c968c5422a76bfc018541d1c66aca91af282567eee93c1e7c314803614d6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/falco@sha256:846392fd8a68a8f4b94f1cdf00adb5e862fe1906f3b869367fd7c473f036018c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/falco@sha256:d3054e356e45c80ee4ab85aad5e4e951c0229d8f4b6f2ccf3359daedd0b265e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/falco@sha256:458d06de3eac17d8e41fe6fc245aa877961cf6934f612c203b4cee0c8739e32c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/falco@sha256:7a490d4a729a8f3ef78de8c38681d3ee0fa5529ae70429e30f90f1a10e2b51ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/falco@sha256:045206be55ad41a9151aefb22d97c04e1131cc46b38a5e20d89fd1bcb1726ffc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/falco@sha256:926d40dd7fe2bd393f038189e9aeafad8522d7b27e942b65c4b2907009fbe00e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/falco@sha256:0709eb5eeed19c8115aa67d822116c58b72e2451510478402efbd663b0c24764
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/falco@sha256:3d71b1f006c203d1e4c3a555292379a61cea20e6d555907127c55a5c98e46ba3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/falco@sha256:a49dc11f38a491976d49189e1b282b27902ea7081367eabd60ee66cc8b379dae
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/falco@sha256:19e6ae3c9b6453a28c7a8c57f1aba0baf2555fb11f2d4b1a1f8270ff1fe9ec05
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/falco@sha256:b3f4b737963308a84c68f765ac7f958775e01a5b9bfd70dae56b2064d5bae52e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/falco@sha256:7623c83d71e426ddd9e8871288e42d499021f84a5ff3f9b9de7f4d85f20e6ef8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/falco@sha256:40ec62302932ff3206c58dd092646125175b940a8d87cafb917a23aa1acaa383
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/falco@sha256:27064e712fbc2ecb807607830f80e9a58bc563ffe15cbe52bc7ef517359e6512
SPDX SBOMhttps://spdx.dev/Documentdhi.io/falco@sha256:0378ffcf6cd44341c3a9382015e79492b949ade3107887b8e215c62fbd7cbd3f