dhi.io/go-jsonnet
0-debian-fips, 0-debian13-fips, 0-fips, 0.22-debian-fips, 0.22-debian13-fips, 0.22-fips, 0.22.0-debian-fips, 0.22.0-debian13-fips, 0.22.0-fips
sha256:ec1e3f1acd68a597bf5947f06adb2b704421cd1bbf53536e67406050c3c8b31e
Manifest digest:sha256:4c7ac061c042d425727cb4603fd6cb94e8e300b9b05c7f6b3572aaf96a93f955
Size
11.76 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/go-jsonnet:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/go-jsonnet:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/go-jsonnet@sha256:36969c540f857723920174baffb75cd966c09c6322137fe5672638b483726cef |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/go-jsonnet@sha256:69bd02837d8c364a7cb575d8b8cfe9f5a8940811906c40f51a4e4d465eb8e247 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/go-jsonnet@sha256:f11dc7e6ed113de03d8a85eab61af790048fb72a948144321dc280cd2cbf1cd7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/go-jsonnet@sha256:55bcff6428f06924dc925512cd5d39daf1a9d7eb29f9efc12253cbb2e11e96e5 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/go-jsonnet@sha256:20b1154f61b68e1254c93c808ad9ffd532f78006fa3664cb3360f49c2379244c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/go-jsonnet@sha256:b05ab8522ea3268feef275949937e48627e0a105255a0dcc515ec40cc9afa349 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/go-jsonnet@sha256:014fb1442fd0f0a13a49d634cb8e3a9bde04d3a125decb879f0757eb0f79814d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/go-jsonnet@sha256:b1e50d623008b13fd7faeec7f3e9b40d332d208e1f91bd617e8ea695de71a4bd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/go-jsonnet@sha256:fc0f1c7a8ec7f836f40fea4915dbf8519e517068d8b34af9f2ae45dfe33d063f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/go-jsonnet@sha256:2f30b7fa036b5c4ed0d516714462ab52e9581d5bf1cc1a19c6b08914e6d73441 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/go-jsonnet@sha256:b512ee8933702c6fbd5af21f7df79050b15e8f790ba73dda9f53dd375376fed0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/go-jsonnet@sha256:1f75fc2aa753bcd7fef15ed5af453f1cb012d4256308100eec689f836d3b97c2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/go-jsonnet@sha256:de32fcb8c561c3cbb3457a927ad35644049375fad21a1acba2d85bf4d853b7de |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/go-jsonnet@sha256:d980cb39e5378a73ddbdf6fc810e6cd439353b11e22f579bc4db833e26c2f66f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/go-jsonnet@sha256:3773b4ef046112843a565bc4d29e2ce25b044c3024a2f688fc915ac8b0b50fb3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/go-jsonnet@sha256:79a57ffc97103dea523e8d9bb1918c3ebfa9b171add88abe0ab6846f75da4748 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/go-jsonnet@sha256:9e99e4f14e193ecc2212e5837b269f040762e43a850e25eec7d4c409d644f2ab |