Sign inSign up
Flyway

dhi.io/flyway

Flyway 13.7.x

CIS
linux/amd64
debian 13
Tags:

13.7, 13.7-debian, 13.7-debian13, 13.7.0, 13.7.0-debian, 13.7.0-debian13

Index digest:

sha256:b32fa1f02dddfd18f71e7a5859189eb8fd06d146916ecbdb03b612054bcc9108

Manifest digest:

sha256:13ba9e99ac89514da5d3dc7686dd61b3638b5b6770e951f1a99834f3bbb307df

Size

350.36 MB

Last pushed

15 hours ago

Vulnerabilities

0
2
5
7
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/flyway:13.7

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/flyway:13.7 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/flyway@sha256:cef7b84b59dc449d6d8c7cad134b9832b0fe4d4d7ca2424075e2c09bd4e03ee1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/flyway@sha256:c744b28d9caa5348dcb8cbd2847787feccc63faff6d16bd188f3b9509dc89c53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/flyway@sha256:3de06993e94cb908e1d368cdac8fd1d49d1742197542081e5c8b761134c74bc9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/flyway@sha256:7a4d5d9afd9be043f31adb79c326f402127494a9483fd3ffd3a185b52e91bf6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/flyway@sha256:ee3dbf1f2a3fa70b479bf73f3eda770abe689c7a7e97e3f14da5eb8c6f1f757d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/flyway@sha256:8842dc4cbdc81360842ed51ecf195f8c23b53d112c99b331bb6c4e16fdd851f1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/flyway@sha256:35551c17926770dc86e2db0e9a12df5f1877c68074a8dd732375839d4e3dfa8c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/flyway@sha256:6ad5aa1c92d8195f5090b313ba6d88f2e587e79fc22ebfdd1d715cb1fc82b0cd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/flyway@sha256:088ecc2b52b712e601e08edea961c1b03e10adbdb9fd1435f33167e6a2c0ec15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/flyway@sha256:b9ff686c7f8bac8c22dd3890525404521da364a226511020e5763926425ba621
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/flyway@sha256:badb5fa40a31904a608423b10b6e62cdc37bf898d3072009432b796739c78c5e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/flyway@sha256:a968f9fbf2b4cbb31d70601df6c4f606bb9467a9ab261fd2aaf4e1095fc5f2ea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/flyway@sha256:33c7ac707d1d4f1f48e1a9105ffbce8b4efb49163d8b7dce0734096f480ae4c8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/flyway@sha256:71278941c54e90e6bc74a3c62c8d06fa31bc2e993d32dd44959459134aa44789