dhi.io/flux-operator
0-debian-fips, 0-debian13-fips, 0-fips, 0.60-debian-fips, 0.60-debian13-fips, 0.60-fips, 0.60.0-debian-fips, 0.60.0-debian13-fips, 0.60.0-fips
sha256:ed02cb0bcd58121f40e74ba4156f8334097e3e3f330aa104922f2565fb3e4df2
Manifest digest:sha256:bfce0698b94101b42d09f48b549faec2ddf47d839b2d4f4632fc2b493e26f480
Size
31.52 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flux-operator:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flux-operator:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flux-operator@sha256:7b77a8286d65ace4f64e57dd3904fd4056dbafa200e6842982457c62c718a627 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flux-operator@sha256:7df17fac1de7340542199fc625c5a3e31dad793b320eee327421610539108fee |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/flux-operator@sha256:828cbbc4ff16f722fe99d7f2ef7c86af03ed3c39192ac665c62dd4b6bd0c8649 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flux-operator@sha256:4b23d6ce247ae3b896cb57d127da349da6830cbe8fe24737b8a69081767ae965 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/flux-operator@sha256:e095291faa3a3fef7f97286ff1b0e5286f869bcf94df2c22b16b8607d0e9c3d1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flux-operator@sha256:e0c960f66cde558b601ee2cc896c9814c32266dbefc9f6ff8575f5bca7b3faa9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flux-operator@sha256:67aeaa9abf211ee9840ac0497b4cb783221794e83cd967383d89e65e0f7fbdbe |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flux-operator@sha256:c9de94e7e670e6be990615ba73900dda9bd683194bab995a1fbbb767359daa48 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flux-operator@sha256:9e3efaa0e6e1f63161619f3eb7afb2d1081db509bb11f10083c608d5270e5c55 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flux-operator@sha256:495937f19324117ac27b4f272d8a3c2bc9418cfff350e5bca663c29d1a3ca9e7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flux-operator@sha256:fb5d99088fcf63198fd0a0029e2e6e2a342c0932dee7e96204118eec987cd1ed |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flux-operator@sha256:f5d6f1bee3732877acb46ed09217bb5993e0b39641a205eab3178a67e06fb24d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flux-operator@sha256:eb7abf8da4585d5242eb7160d62f745176e17de97b297947cd4be4fa9c8ebc4f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flux-operator@sha256:6b2faeeb0deb1c74c56f341b655a0d52af28dd4ffce74c57a1c381696a41885e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flux-operator@sha256:5dc8f354caca2ad56e1f72188818dd0b4a7691f55ad1b160d947595b10b1e9a5 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flux-operator@sha256:8e688d40cfd4255974ed7865437da03c9f322091802e1880b9e279b41a66312a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flux-operator@sha256:2c5e01f008dc2238b1f8f2f5823a2be2741d9c206adb8d46725fdd2a438d499b |