Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.60-alpine-fips-dev, 0.60-alpine3.24-fips-dev, 0.60.0-alpine-fips-dev, 0.60.0-alpine3.24-fips-dev

Index digest:

sha256:dd11a19f79dbb128fbe3a77f7e49106a9502f1ebd97c70185c8bde6fd6fb0a88

Manifest digest:

sha256:d1a18d52ce791ef1b83a072beb330ff477d8293115dafd66cd64660ac9983457

Size

49.90 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:e299558d8b7a605d68c843e7c645623e6f17de58aed4b92a2121e4d2c0edd29e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-operator@sha256:8359f2ca902fd819021b644d11185a1658cd7f19990bd37fd9d961789cb84053
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:195a28955ec37f2e4f74129a60d4289d99ff553970b67826b176d5a1aea238da
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-operator@sha256:4f1c0938e801472e2b87bcae76f5fa67d051837a25f214b89a5b101e2b8796c0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:d8b99de9624ca4b0ac0dbb117e9870825ac6835617b191e8c48ed716b7f520db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:67feaa1b286cedc65977b7fca7f3d23e48964a3edd2984739bca06f65c3de2b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:139428b12ed04ad2efbd25423d4b974a7367ea67704f8bc643f9f49cfd64a3e4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:404754f6dfb19b9b965e600f2d7b1aab91dbdd8ac41d6f197d2276f60e0de49b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:d9359874c304e64f00efa91fa0c98aa132ca5f95d2221074b349ff473a38d587
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:2ab186a8608e010b858ec5e7c90d56f81bee188d571b367f9ec0d2fe1ef381a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:ff82e5638030c5f2678a926acd4a86f423adce878068da904f7a6c255519533d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:be748e902feceb77bfc4a7eebd8c0ba131f838ddc76ecb160db3fe577ed0ac26
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:c5645718c15e6ae435cda0041b1b5e6678fa0b4f3f24f0a31d52ba83e6a9dcca
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:78b6ffd3a3f34fb0390122d2697d5f75dcbcddcfe90a74633799af7d6ce4e4d9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:9e9eaf28da49906d922a0b833b4c33427a9a759a0da28bf9d392902d27382eac
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:389bdf5eb76440179b2a2b1c8b5d6afa2f86cfe0ca04c58595441a80e606d295