Sign inSign up
Kyverno

dhi.io/kyverno

Kyverno 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.2-debian-fips-dev, 1.18.2-debian13-fips-dev, 1.18.2-fips-dev

Index digest:

sha256:6c507e2456459b17b726c4e1b0a55bacaeeef94c3163c9315a54e71fa4a873c0

Manifest digest:

sha256:ecab1a03ce20eceea1dc7b8b08232219db937147b749c6cf3d925d5a8822ec74

Size

91.49 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/kyverno:1.18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/kyverno:1.18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/kyverno@sha256:d2809f406d3c24540688039581d658e99ca832ff6df2f742dbee38c1b74b2ad8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/kyverno@sha256:831e06db932f6e6666e9169c33c522d28d98c87d855ff350901215d3d373f11c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/kyverno@sha256:379c566a70a17b1fe3c8a690c8e9c4659c6510972f65786aba0ab1a106af4d1d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/kyverno@sha256:7fb549a47d078a9e80034f8f1dcdc112b41078271c6190ec2505e0dfd4dd55f0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/kyverno@sha256:dcbdc4f5560861d98ecf5a2bef467173cdb8202a77004150c9036f9d5b7c28b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/kyverno@sha256:e235ce8e4204206718118acb2410203e96fca3ccdb199fac5fe4f10670b10966
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/kyverno@sha256:e059e0cf2962159d5fbd44bd6bf3f7e0c65ed60a4b7978f3f2bd071d2182c480
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/kyverno@sha256:fabcc59cb8ffbc281d87a15aa4746ea89c5c7054c2a6d2bb6b8457e17374e353
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/kyverno@sha256:3597ddcd2d2ce8c1db19ac789a076cc94909359cb973701fd903b201dedc5e03
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/kyverno@sha256:7a1e83cbdf6e7c76e7c94e33156506d2f3aaf02e15a55c0b35a99ec502d26473
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/kyverno@sha256:0192dd8c241cab0fd310cc6e2d6da4e1615c4c248171badb2a75e64aa6e5faf6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/kyverno@sha256:753956cc30c549a6b09f992ad80444a1129d93b50263dc44811ee5e75792cf2e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/kyverno@sha256:101200df6c6297151667d0e55270d43902972968e0606f26b619747fe98c774f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/kyverno@sha256:0afbc667ceb24e7a76a43adce5305c782a668595a80b523fcd9fd7cb66c39dd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/kyverno@sha256:9cdd8245172ef37ca1b59dcf32d026b53548d4f133e64f1e1e93f1abb9ae1ea1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/kyverno@sha256:c674545f577a5a4be25c6256a77c21584fafc7579937e3fb1e7418d370dbe257
SPDX SBOMhttps://spdx.dev/Documentdhi.io/kyverno@sha256:4ca4151fa790e4c0f2d03012cb0486431085b7af4e9bd2b8ffb84f088f4548ae