dhi.io/k8ssandra-client
0-debian-fips, 0-debian13-fips, 0-fips, 0.9-debian-fips, 0.9-debian13-fips, 0.9-fips, 0.9.1-debian-fips, 0.9.1-debian13-fips, 0.9.1-fips
sha256:fb6b11dc496d4a5c44cf6f1adffdca1c27ec5e5f7e901168e18eb39dc50622fb
Manifest digest:sha256:dcc6700567b69a36361a42e01f0276e0d998662e6ac70a0414c7191807e89cdf
Size
61.05 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k8ssandra-client:0-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k8ssandra-client:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k8ssandra-client@sha256:3320d76a24d866a522572e431aef5126e3d41b8413daa88f6857cc4dc0301bda |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k8ssandra-client@sha256:100e9e8a317d8be0f41b367f07f9de40b323b5e9ac91ec3065b5623a242db309 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k8ssandra-client@sha256:adc29609c8b505ddc77c4e82e516e3ce3a3656c0784de901af70a726fb1a75c2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k8ssandra-client@sha256:3cb2fa9b94f1ee1cc323ca938114e0e47ff6589588399046891d172e3d9432a3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k8ssandra-client@sha256:5abe07076e669f6bdad0ba40b1754885f6ed545d7f83fe5761fefc492dd7be4d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k8ssandra-client@sha256:b302cf225d4b9f3dec80b7d71344bc74b15c6fda65c7841a84df2628db74f24a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k8ssandra-client@sha256:b3cf69b0eec0c17ff7dd04010b65af374ad175222b758c188300a62c6d70d3d9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k8ssandra-client@sha256:70c219b444e281287d7bdbc830650cae90a348d5ac9cb5f05d33e891306f2323 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k8ssandra-client@sha256:f2b7974c20badd8dec374225bf680923e0e785be32874ecd4adf519e4b9f59e9 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k8ssandra-client@sha256:760a17d2f18a3d5368a5ebd64a7aa8f26d80d5cfc225b93d1bc624386980789c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k8ssandra-client@sha256:59c8bf3a64b3afd8a9fcb2b813c715119392179d3eb0209030cf23d0bfe4e6d0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k8ssandra-client@sha256:8a5e267473715f4903dffe18920383d3845451c2857a685fe3205e64e087ee88 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k8ssandra-client@sha256:1504976d05e6584d9eeacd69d972517de90b3357a0be56251ebe6d797a3dfdcb |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k8ssandra-client@sha256:2191611bbb1314632110bda295a95205393fef19800fe1f931f9252266c6677b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k8ssandra-client@sha256:63073e79a6446196c7577dc09efc74e0f116c32efa11c3fc1aaf44a19edceff7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k8ssandra-client@sha256:3ca90f6e80ceac285258e859193ae13098e9a7da53f79aec09027811568e8590 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k8ssandra-client@sha256:b520e8b5feeb3703509c0969260d4d4483d13ad7cdf85992380be56969aa1df3 |