Sign inSign up
K8ssandra Operator

dhi.io/k8ssandra-operator

k8ssandra-operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.31-debian-fips, 1.31-debian13-fips, 1.31-fips, 1.31.0-debian-fips, 1.31.0-debian13-fips, 1.31.0-fips

Index digest:

sha256:4583f4e4ff98bd1150c0ca7762433675f2c7afeeb912f013694f17a9f8697dd4

Manifest digest:

sha256:faebc87acb953e219b7fcb10e5403fe7a9c77cceb5fdbda41cc163c4313d82ea

Size

21.86 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8ssandra-operator:1.31-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8ssandra-operator:1.31-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8ssandra-operator@sha256:243b8af214cd9d32b8486faeb7895e8a6cf1a6f3704990f6fac7c6f2565d0bdd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8ssandra-operator@sha256:0de9dbdf89db77100afedc6e60d0ee4fb00cc0957fbd22eb7484f9a25f043c75
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8ssandra-operator@sha256:34ed7cafc44f382a766a857377364fef581574ccbfcbf9d2e16ff6cb18003950
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8ssandra-operator@sha256:1317221fde360a5ef2fa4d3e8b420368f99f0e8e75b51c503680e9cfba333735
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8ssandra-operator@sha256:370702cfaab7a2c6975400283f0c25dc78b4dc3b616cefc4eccbe1d514fbe4e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8ssandra-operator@sha256:36486f30232343ad801bf512db9fac7899995673f386777907b46fce66939aa4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8ssandra-operator@sha256:192601f52792a2ace7a5e8ae2f644e686c9364ce9a6025416d7e51f76c105392
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8ssandra-operator@sha256:49b0840cfa89e7f03d592dbbf137d0c4a029eba23ac78c417c8affa2f39b8068
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8ssandra-operator@sha256:758de6ba6ad734ae92afefaf4da61d86b03e3e3486848c0f8585933c6c63ea78
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8ssandra-operator@sha256:717111e3afeaebb8b73a8980ea09137410f89ce8401c4b9bb6bde18ac595b282
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8ssandra-operator@sha256:8f6e45ebd3c1cf9bca103b586bd3ee4dbeec5f92384753440e2507a86669a458
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8ssandra-operator@sha256:4255c1f927a9910e203d4dbc486fb7f10941d3b670300905277d231b0c5b0b25
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8ssandra-operator@sha256:2ad635fffd43e0d46b6960ed851a412bd0a023bc75f9ebe5cc56569d43e53170
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8ssandra-operator@sha256:4bf9551f3ff96f51b0b959a7e6a174f77f134323a3092ab5ab42805cf849447c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8ssandra-operator@sha256:3741b7ed250ad44e2fe19c1b8d70f58bde11de6195e99316e313d054afbad0cb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8ssandra-operator@sha256:9e51953b3a25abf176d7e4423c888866c640b6893e62bbee77ba048e42dfd314
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8ssandra-operator@sha256:171134612c8cb440fb7d8528d7b989fca68a5b1d619748184e573e4c2acf3ef2