dhi.io/flux-operator
0-alpine-dev, 0-alpine3.24-dev, 0.60-alpine-dev, 0.60-alpine3.24-dev, 0.60.0-alpine-dev, 0.60.0-alpine3.24-dev
sha256:aefa3dc446bb2f4d616eccea0eb90c4a66332805bf6d10721a1486776a13eca1
Manifest digest:sha256:66535b400b46747dd918fd233a9c1a704d3b90009f0efeb9ba75c1a2999fefb0
Size
49.03 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:8ea69092fd5d33414a2e9e96955e8412fa2fabb8a4219561fee0f7f22479190e |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:562a0a8855b1be140949ef3b2048bc894779e13bdad25f55c45886169cbe59a1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:43b9c622859f7fd3f80ef3be202b941f2210ebcec5ae91f32e1b690cad021a2c |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:58002323d4ef657a8c543403e624e2a0a66a6e111142854345b41b2b5c666c8b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:e7ff3698fde46a050a6b14d6cc59e53adb2e52afcbb361b49a5127d311140443 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:37b7aa6253a73c1bfd2990b929a76b3cc4ee3bdf3fceee631fce1d1bb2c9992d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:2a206f851131eeb51731713eca1d744bbb932fe9a88725a8ed0cc2671e3693db |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:c50c0323e9107d71343ac17ce4372c5b26cd0b5b507a213e717472d9e8d504f1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:25b76480f60250997dfe5f34ab594618224a43c5ae5be84661a5815237eb429b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:4fbed49be50b534671fc23184f96621b2b4d48791eaa44e79cb8c9f0a50cd3a8 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:c46ef2a84afa2de85ab31ada678b96399f99488ea64e9dfad7b6edae0ccda5c2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:6b11e7628b900b0d1a79ae81d6495e50a203731c6784a209bac306e1d3004c81 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:4c37125f128ec462ddccda9834f734d80dcfcd07f27bacfadee94a66d42525fb |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:b4bcafc4512a430e752770e39c90f17760ba84c6e8e7cf1017f032c66a45fa09 |