Sign inSign up
Flyway

dhi.io/flyway

Flyway 11.20.x

CIS
linux/amd64
debian 13
Tags:

11-jre23, 11-jre23-debian, 11-jre23-debian13, 11.20-jre23, 11.20-jre23-debian, 11.20-jre23-debian13, 11.20.3-jre23, 11.20.3-jre23-debian, 11.20.3-jre23-debian13

Index digest:

sha256:856de57e616190b9ed222b2931effc48de095a17eac6e35492b581b004d897c1

Manifest digest:

sha256:c5a140b5b8de3bf92370002c07207837265c6a1b7ebf526d7f016276a2d3e8dc

Size

293.34 MB

Last pushed

21 hours ago

Vulnerabilities

0
5
8
8
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flyway:11-jre23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flyway:11-jre23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flyway@sha256:12a808340823861a7e338fbc3810b3a9dc7f38a78380a608b0aa6f104f9240ed
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/flyway@sha256:50279ad9d147ee7689391cc97230578d4abbac061912444c93f23dd66ef42d1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flyway@sha256:d7b3ab88307ae0dce3df4249749e5e43fb5d1a5b2670e4d6ab601653825b5872
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flyway@sha256:9b1fbd5ae0d502dc2617de63027ab290b0acc63fc16386e50b7a4417578d873a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flyway@sha256:a13632c4e5d7f4e159c15cadaf52ca4272a795f786b86adad721ff0b01575e16
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flyway@sha256:ddeeb538ee7bec32cd7da09b053b818d0f2977586f06de9080931d2d56c1444e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flyway@sha256:a078d1a2580dda018aeaf99043ff6306dcd84796f33441d97dfa0ccb2a88a9ce
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flyway@sha256:312aaee68de1cdb6c35ef960bd75f7486bd56208b582d3e046319e31c5736958
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flyway@sha256:32372c8b217366cb0cf0fb274c00e97f3593d07b6b3b8841837902a850dc05f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flyway@sha256:9dd89156860b2385cbb4b915b5e095ad7a25a56bec1cf6e7cf2adbae726ba1b6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flyway@sha256:1134ae5ac114c7fea041538d5f2b1a4672a6df36834f554e3adacba272e5ce27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flyway@sha256:aff23afd0355b798c810a31ea5c962f7ce4729550b106ca9183aa96336ca5f42
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flyway@sha256:b98600a5f2ea0721775e00fe0decee244a83d4e4663b19644b57597bd51f62ac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flyway@sha256:b0d19e6ce26c0ca6eab4810398fadc32c8cb14c875d45d14a68086d2bb94f2b7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flyway@sha256:3f377bc06aff525bd6acad4d017cfb54d2a7087c7cce7b8df7bfd143459d7724