dhi.io/hatchet-lite
0-debian-fips, 0-debian13-fips, 0-fips, 0.107-debian-fips, 0.107-debian13-fips, 0.107-fips, 0.107.0-debian-fips, 0.107.0-debian13-fips, 0.107.0-fips
sha256:d5f2a3405f9883d3ab6891acec7ef82f8c328cec6d2292e29e94d6a8f1c8be63
Manifest digest:sha256:8fb8790cfcd59d89e2d58eb8bb6626df7b8f62785d48a774e251a6f037e62543
Size
53.93 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/hatchet-lite:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/hatchet-lite:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/hatchet-lite@sha256:2ec228189e87bc7f88b34ef87f2d52f5b129a34e01cf263559775e47f948f7ed |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/hatchet-lite@sha256:70d69e8b6989885ac8340c39bdd7dae422cbf3ab4d29ab9e7f15db413d4c11cb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/hatchet-lite@sha256:75fb4e8e8916b5c05818f55d0ea00a5408b5e739170d63dec3f4e8d2ae79c2ce |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/hatchet-lite@sha256:4356bc8cf155e3292d7d018b59d5bf190652be5e8a372f05257620c9e804ff26 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/hatchet-lite@sha256:13754d29287088f88d1a89db886585c4a21654929c1e703b3769c4095c3586a9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/hatchet-lite@sha256:38f645c493018240caaff376740221b3422a1aef2cad0700a8510ffe16747b7b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/hatchet-lite@sha256:0c7749d32f4706e5e2ba7b051efa548214f84baf401594914e1f8cc2cc713cb0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/hatchet-lite@sha256:b684c3aa0e49bfc59220fea5664addadfaa397d366620626258b81e12c046d4b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/hatchet-lite@sha256:48e3a73466500a7ef2066343cda775b692801d6f04bd2c6d7d13dfdee2acbf12 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/hatchet-lite@sha256:86a601455900ac693cdf34ccab3e196cd18ef16dd3fce07d4cb36b9e3ad8b10f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/hatchet-lite@sha256:2c36cb37d1b8899ad6dbcb544cd8e02ba9149335a4eaa41d800f5bafd0f2f366 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/hatchet-lite@sha256:1372a2aa2a9551d827d7bb88ed657cbb714fa9f694bd41703398138663062803 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/hatchet-lite@sha256:b62c13010b059f3fee43afdd5698dfbb450dd8d258fd60ab280bd79fd23e6e5b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/hatchet-lite@sha256:3d0d8d495df1aa8e0f5c4f111fe8a8852d73e483c7e269bf5061851eeea8cdee |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/hatchet-lite@sha256:eaff34dfb4ea83795f5ad7a10e72e9377f7cf3adb6ab3c6b12b54de3fc312bdd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/hatchet-lite@sha256:9142eb86571f2d7b3989a30e8fc73634301a3e5d78db33e820f6cba22a57c769 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/hatchet-lite@sha256:91fd0f3d4b218a9e72979c9a6966273c675d14d8dc49005e70db8c9d2aafa2a9 |