Sign inSign up
Flux Operator

dhi.io/flux-operator

Flux Operator 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.60-debian-fips-dev, 0.60-debian13-fips-dev, 0.60-fips-dev, 0.60.0-debian-fips-dev, 0.60.0-debian13-fips-dev, 0.60.0-fips-dev

Index digest:

sha256:07a7c16fc9f84f9191d029e844933c92ce547c16f80a9550ac793d9af548c0a9

Manifest digest:

sha256:46151fe9e43497fae8790f8b7a5b2e85e6fd3d768c217ef72863f8a8803676df

Size

69.31 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flux-operator:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flux-operator:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flux-operator@sha256:f23382621c74510c6f0430738d510a70cd5e07fcb6ff6f650c0dfcbe49f99173
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flux-operator@sha256:9c7ca2d7723eeb12cd772cc10b75137614145f68dc31e0b6817ca99a39ca154c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/flux-operator@sha256:12e509468945a6f473531ab084064a5884d147423f5fc95236f10613ecaa1a00
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flux-operator@sha256:89a72e59e9031fc198df9c6b96bcccbf67213fd8fa308d0ebeeebc68f814ad1a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/flux-operator@sha256:6f369ba5d6a3bbe9393ead4882c3952a3a232fd070049d2a540e65e70319fb77
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flux-operator@sha256:2a200377d44384f39bbb27bb8fc0cac2ff6d6247613881c56d45ea9f9aad544e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flux-operator@sha256:c367846e59e7a22de70a0cc36dbd880d62c4e7e26bf7e4ecef6fdda93319963b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flux-operator@sha256:ce69638f5a946a544505d1af47f66ec2f7ac164b809d0a8c9271a09f3ce22fae
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flux-operator@sha256:b419e5c1237c5d43b0e6648bd2d679314e5f7e4072a37ea13bdd6cc30438d07b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flux-operator@sha256:0a76fc42d8651f659997ccf186d91084a3addb0e8c079dfcd99b3e6e347c6cbc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flux-operator@sha256:f5b219b8ceb401e051161b161e4b8d126a0ac544112700a229732530c046a1df
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flux-operator@sha256:8b9caa88f593d26ddf1107ef829b47a3604f1e1d1835b5a813e9347a1c7d9e4e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flux-operator@sha256:0c88a3adafcf7a860cade9b53cc81b70e8eafdbe649eccc9ff5614ab6fbbab18
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flux-operator@sha256:d131b54265e667754c451cfd46461849d66f497bb68f8f5f7a8d76c65a3b1bb1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flux-operator@sha256:0b49e3fbc735667974dc281377c809a397b3999a501b49f5a66355f28fac47b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flux-operator@sha256:a44cbeec0c4599e6c92c8c47be557d9b50c80ed5da34cb18ebd0c92624cbb098
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flux-operator@sha256:41021a3ba61e1aa1fe5e2d5ad838fc81e019651e34f6260305c9e876ee9b4c34