Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.60-debian-dev, 0.60-debian13-dev, 0.60-dev, 0.60.0-debian-dev, 0.60.0-debian13-dev, 0.60.0-dev

Index digest:

sha256:750b94913e1c3808eea46248ef647fe5ee733b206d1ce1fb417ea44bd9e26db4

Manifest digest:

sha256:ee75cc4044c792decaed493a1206bc626b9946909976594b964b1e175b4a9ea7

Size

68.56 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:df517b2657db5fc436f6b8d19567e4856507cef964a79208c9deea3906113831
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:dadcc5c43edc943337805c619f93ed68a0e381289ae5d9307ee2c555be4462cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:c2ae3079eefc78bd97b4f498018b609f9832c5034fcb0ac82cb6d33eb38b8c22
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:b010f4c285b3d7d05bb1d21ea13983b51e7af91784c07c590b3ef64298ba78b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:0a1503e8e68c9fb1a6cbcad050f7e3a58caceb99f2d9eeacc8228a72dff8adc4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:4b772f6fc97617f4b706f0069b971e8774e26e72ca0773c441947ab87323911a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:8aa2d8108dc36e4867e1b3dd8c01212d99fd90b9de8f28265b77d5c612e24d93
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:a754dd05d3678e76a604722b237a86a42708ad221e1440a148a6893b6157427b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:162bd07f41c22cb0e01d74102e0b4b448e36a03a57785d888490fd1a97b8cc54
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:99c1c34e630db76f6e98f287ecdb5e2392f3120a0b74644c72b42d5e539257de
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:ad39b140b6c48aba15170d21b2cb2742f103cc09a1143e1bde4085982042be77
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:3571233f6c8d668f011334e689312dc58d066fbc40dc7170b479dc531c6444e5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:7b79cdad55a130f77d311ad4f5d453964654b8e07138a11b80e2fc86402fe1a5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:8296d613233154e96338c54827ff18abd3f3dbe3679291ce97ba0da707374b45