Sign inSign up
Hatchet Lite

dhi.io/hatchet-lite

Hatchet Lite 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.107-debian-fips-dev, 0.107-debian13-fips-dev, 0.107-fips-dev, 0.107.0-debian-fips-dev, 0.107.0-debian13-fips-dev, 0.107.0-fips-dev

Index digest:

sha256:2057fdb5a7e0d1bf1eba71765aaf550fb1578b20770ec04c8874854702b184da

Manifest digest:

sha256:a0679ab9cb40a3f57c77de586e8a47c2a9c50f1f74ddc181a978d3ba8c70ca64

Size

68.32 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hatchet-lite:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hatchet-lite:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hatchet-lite@sha256:142e7a9ed72f46739a28352c4d28f1e1c32e92a2c1310a77eb418b2cb48da21d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hatchet-lite@sha256:4de70f16ac3c2b8c461ce1cd802b2400f6799170f676ae8efc8cedc64f51c8db
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/hatchet-lite@sha256:98ec50b605010fbeaf760325928952934e9a74c8a1f234f4e01b11f6888f6888
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hatchet-lite@sha256:738b08350239965fe9a5cc681e35f064ea62e8fff65c176a4a8d8e23670abd35
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/hatchet-lite@sha256:bb05abc35f4569caf0b119069e4cd95ce1ebff3eab9131edad85f210301f0c45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hatchet-lite@sha256:e345698c043b99136e8277bae867e49be2645454ad68f9007a38a1f9b5069248
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hatchet-lite@sha256:5e8103c3508882134eef7e075f2f6126ca56915c87218794260d538ff8550a27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hatchet-lite@sha256:a3cda5c4de0302c3c84501482b1a6d01faf5edc397501560f918b172866083e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hatchet-lite@sha256:8264c1315816afc5c70cbf7c2d9c9a6e50052c4f0b11959f10d5f36b43a11ab4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hatchet-lite@sha256:64e3ebc16eac55229f9a83b865347b65ecf8d03d1bdeee8c4f9115fe73e40b5d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hatchet-lite@sha256:fd449e52acea59cac658c3822630380b0f3c4cf2c07003b88b31725b3f1f1f7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hatchet-lite@sha256:9116e4a5617246dfd8407462fb10a67ca1094047ada1650b10d3473db4672279
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hatchet-lite@sha256:80896c7584a8eb6ee0d794ca2e883f405b53d9f50f92afd8b47d0bcb7dfd379a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hatchet-lite@sha256:f260f9b50fd6320771ec3040248fed14aa87e9f91bf4abbdc00c1b503a59a021
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hatchet-lite@sha256:e24b2683713c24dd9e705edd3d2ba6bfe7dc149231a13759f4149bb1ffb1a4fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hatchet-lite@sha256:955ac62a1235311a8cd85214b22b226e289c4f50b6eb5a11b13df23b4e7ba489
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hatchet-lite@sha256:81fb9f12e5b2e98d7dc4461f2789138543e19d48c0ed5e442cd04dbad6258e32