dhi.io/jenkins
2.582-debian-fips, 2.582-debian13-fips, 2.582-fips
sha256:7edf1b8cd8ebd5c3aa33789ac280e87797429917bf419c83970c0348614f0f58
Manifest digest:sha256:f2eeab9319c59efb9bdd044f1f87cb5fa4016ebef9e82c269ed30f4958ff85b0
Size
143.76 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/jenkins:2.582-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/jenkins:2.582-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/jenkins@sha256:21329156f1d4e4251283479c51bce42672062273c796ddc14b150d819a8755b7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/jenkins@sha256:9d0d7ac4e17b9c70c275a09b110358e06f7d857962e6d337373002c47af1858d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/jenkins@sha256:9967d2ea141c2570b8d351d717ecff3d692dec8ad19b22e0a829db51ec27222a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/jenkins@sha256:211273e7fc1910dcbfd8ca2a87be8c27705da55153d8cbda0b79b14314d8e9f2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/jenkins@sha256:12dbd6227a05f2a18a3e3e8079cbb89abbcca05c81b420a166e50521a9c7d9c2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/jenkins@sha256:4c8232fd8b0db6795c3f1bf61fb9ead12a5283c48701775ec4de65b974faa402 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/jenkins@sha256:c54f8c9d4a1edd5194d6f4970c24cb9ffccebf8d09f12fa734f2285e8e75c771 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/jenkins@sha256:618f66a1fd1a2e1d5398fa27398a0fc604039eeeca7b19abd7dba03185403ce3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/jenkins@sha256:79d1a3f11a3d51d030501e6842518c5c2c9ded1fec2e67f73e906ef568038656 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/jenkins@sha256:c160aaaf49929538e5ba5f6bba7af67d4587459ed787ccfdd7e60514eee4b86f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/jenkins@sha256:660013a7479160a8c53cafc38b732db63d2f5245d1656ab539b825f227fdec48 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/jenkins@sha256:7a30bcf76813953026deca61a60236831d38a77afaddd968beeb9da8aa813716 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/jenkins@sha256:308c64bb74247c5995ddbc1d841452e50aa8725fbcdf22a7301b3a6213ce2c4b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/jenkins@sha256:dacacb92e1c13e9d2c5decac7d43fcc8f02923a702b6bce5a7d36566aaab0afa |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/jenkins@sha256:c6f5b619bb0e344c98047925e0e8795e83a2576d92c75bc64123f914d73f5a3d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/jenkins@sha256:bb1b8c44a5d554f2c3e59a15f78f0b0c4b28e3d2ac6904c28664784855d3f33c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/jenkins@sha256:87a06c1cc6f06624bbcd1eb6ffbfbee53b296eaeacf4c83ea9c61c79e8e112ba |