dhi.io/flyway
13.7, 13.7-debian, 13.7-debian13, 13.7.0, 13.7.0-debian, 13.7.0-debian13
sha256:201f7628b4e5c324194006c96c860665ed2989380a8544afbb759c5ebcccbd6f
Manifest digest:sha256:c0694e3b655e5fc2dd680cfeba51174b47a4066833da057996e9e3e58263044d
Size
350.36 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/flyway:13.72. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/flyway:13.7 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/flyway@sha256:b04e77b4e2c74f495181e202da10073ae3ebf12de91eb8297624c7c125d5f5a2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/flyway@sha256:8cf567cba0ed954b243eb5a80401855af3e65e75543cc8ed81b45f5994ab664f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/flyway@sha256:b64eda3e4badd67b701c1243dfc4ab145eef7e9085a4f462c634471a5220b014 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/flyway@sha256:32be1b6e7d8a205925abc4d15f10dd1de81140f7b376177cc96758ccd115b5fa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/flyway@sha256:727ac2943c709c3ec849238698d49a8ca674a7f417269c7151ad1bc2cf826c6d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/flyway@sha256:17bd96c325628e53653f2ab6371fbb3aeda2b598c1b52798b7aaa4d3c33f20bf |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/flyway@sha256:9b7e7653bab3342ed4c82a7be9d8de8f626f18399ab622409cc358b776019a13 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/flyway@sha256:31d1af113ae28fc282585880c5188ce51594e1cb35dbf9b5401d692eaa21419d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/flyway@sha256:b924d6b80073224edadf35b724d994c886a135dc8cb321561f76fe842fd4d15f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/flyway@sha256:aac9a422667811a2ff55352b211696e9764a2566c1445f47720163350b1fdcdf |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/flyway@sha256:0864a111e133c5680188beb1ec06b91e27d7283dfacb61fe0d72a31a5800f66f |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/flyway@sha256:6281210df4ddfe083d1ca8bb2c85176e20c68be1930c39048374d4e55ba92b70 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/flyway@sha256:71c3bef79366ebfba9fd5b3f9872434c8b4ab2cd11c8cbc77a02c2a9096afe5c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/flyway@sha256:f6ed803ca12279b8b20afc079649aec3943a35d033c67db32fe853b81b060e06 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/flyway@sha256:73693b75cb298c6411e2d1090fdeb81ef863ff3e6c15d491aeaf68b2b2016033 |