dhi.io/k6
1-debian-fips, 1-debian13-fips, 1-fips, 1.8-debian-fips, 1.8-debian13-fips, 1.8-fips, 1.8.1-debian-fips, 1.8.1-debian13-fips, 1.8.1-fips
sha256:f019caa700595f25391ba1e8a69646f017fd4022888305ed473681ca63d84ea2
Manifest digest:sha256:3052f9eceb63a6bf2d1e61b67b062730bcc21afd9a7f08ba402157f02163c191
Size
24.77 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k6:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k6:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k6@sha256:6172ca0333f3d9772c7091846e718fb145c51d63365097bf6c7c943c6f2249fb |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k6@sha256:a9fb0038aadcb0909b9731dd4ff6f429d28b414c5054ca3ec30ad75418fa72f8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k6@sha256:a2a49cb50aa8f2221a03477a18456fa56a7f780a2b0fbcc7a7c474b175734a78 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k6@sha256:39fc50e3c9f7920ba6f5b9b6d18404d637c6d2db367cbfa886626549eda88461 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k6@sha256:24220715e1e09aa27cc13147213d0178eb4c31d7790591f78a5c49a0229824aa |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k6@sha256:175e8e732e486f2a46cc5151c1fca5d32a3b52c6d6a2a2570347664230a7fc7d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k6@sha256:539b53e9c38af407da4bce9ff9edd6c7f6c1a6bf72d1f62cdc87e84870535a3c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k6@sha256:0791c6f28e77934da79454b5c0437d07fd58845f9c58c83773860b9f9c0b427e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k6@sha256:283dbc20eabd51f016405053365a665d8d56ec09df79b8c02b2ba45ec9ebb583 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k6@sha256:c7d8a7adcc31777de48a223fc8a63045eb802ca1706cf81e7d7ad61494715049 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k6@sha256:3ceefdab379112160a20c9005d125f29c0bbf6a39586b7d593c466b814ae0ed7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k6@sha256:4ed47a8025cffd9caa53082d919f1f4b501b82dcb9bd2eb35da1cc48d08a50ad |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k6@sha256:1fc62852ea1e843aa8159df55490e22fef6d7df3f063930aa9ceb8d37453e688 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k6@sha256:590919eb3446c96d1ced39d20d1f92439e6f7d76864a886db4b0436a68158992 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k6@sha256:f9c01945cb580189fc5849d82f907d86c9836a172b2f71d45d051780777f83b7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k6@sha256:d064d39906974f9618e7e22c2e77161e2e8d90f5c1200d79f916f24e1da63919 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k6@sha256:07da601dc299607c197d30bf60096faf22d8c326f2f63597a95b95f49ae97803 |