Sign inSign up
Helm

dhi.io/helm

Helm 3.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.22-debian-fips, 3.22-debian13-fips, 3.22-fips, 3.22.0-debian-fips, 3.22.0-debian13-fips, 3.22.0-fips

Index digest:

sha256:66ae31d905b49b8cb2876f4e27ba6bc092360add36af113db89b196c494d2bc5

Manifest digest:

sha256:29fe8a70f3de0b27b095402f4852034710db35f4c5f9d0e16b91150627c055af

Size

27.02 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:076afab5df5ad4ebeab8314fe2952365b1a890d1cc667dc3cd6a8b0dbbf2481a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:17e4524f5178238087621a207cdd191d245c3717ad238f359edba377052be771
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:bfe5d5dbc004cfbbaf466475fd6e526b0a90f08817c94f1ecdca8954e4498d1b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:9dd520159beb816b9cbf5ee2a00f18b320af92a6a95671caa215440537f8bf8d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:bd09119051dbf25d285dbe7b1275bc56e3a0cfdffb12f687f0feef823c1c23a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:eee782f4472e6e628f4e232d91aabca467bd060a9eb5ae2f323fb22da4e2b4fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:6f568bc0338ed09635b9ddfb42bb4c108e69cd780a69660d102e5e31835853c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:b56c6d2b6295e1bbdcf0aff2ab93505909eb38af9c020464b6a2e25ad1506714
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:5b199259ecd254ca921ec89cc8423d7edb7025987b56f4af8176bd2f6557d380
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:67e479e6611528ae256197fe6615223956715ea939647db0374fe61bf62bd9ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:0012cdaa5292e85ad47160f0ac4fc1ca30c8b367301eb8fa8f922ab73275f842
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:b25cce7e5f322ed2cd4a2b6c4ec6a0df6fcf8d42003f331a8963f63a6a1225e4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:d8be58957768ecbdb346420e585b1293b3c511565442108b576afcd43eb7fbd0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:4a8127f2105f985760803ef581cc66286645631f9fcb12326b1174e9b2fa59eb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:bc66560b40618d9b6963d3f28603ca0c81fc0bca4ef8de8d5c4c9e9a349b28f1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:17ac3ff37d00ef1ff723b638711dc2efc2803c1c04f643b98bc8b83b3b43de47
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:97c997c233962fd45efe0fb5f42ec3a70d018a2e4c99939a5c7806f1e37dc196