Sign inSign up
MLflow

dhi.io/mlflow

MLflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.16-debian-fips, 3.16-debian13-fips, 3.16-fips, 3.16.1-debian-fips, 3.16.1-debian13-fips, 3.16.1-fips

Index digest:

sha256:669a7e69f4308ad97fd7e2bd88062e50326672a94929c8c150274fb534b6976d

Manifest digest:

sha256:12f417bee67a386618a93c84c4be21b016dd761006cd2e78fbb127f775bbc38d

Size

152.65 MB

Last pushed

2 hours ago

Vulnerabilities

0
1
4
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mlflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mlflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mlflow@sha256:e48f42aedb312a62cf8cfbcf261fb07ce0860f6d57888075be5b905002036665
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mlflow@sha256:e662818223e9c42a5e1b948c5753387185a6954dbe3c7e336f518b409a707874
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mlflow@sha256:b267653107a4e211bcd383ac430ff2fc775cb1e58fe3290206ff026db23e6eda
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mlflow@sha256:6d34e5c90dcdadfb3c6bea7edca0e46f782cac035035d15879dee5b67a58b625
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mlflow@sha256:1d8216dcd3e50708a96f1c2c0b85e93140541f65d623bdb651283409f2fcd5f7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mlflow@sha256:88e974a57c07128339a0668f5d3d65f3fdc1c50ab95746d5d7a3f81dd6c0a016
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mlflow@sha256:bb8217a8407a9c62ce470af8c7345e8459ef8833d992b8e72a65d9a0f3a7d64b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mlflow@sha256:4cae1336b43b1a4a2efb8578bbf93c9f1a372ea8ca764522959968db5b755b42
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mlflow@sha256:ace82af69ac6342be10152af1eb36e301656e350e6291a6dec5dfdae99d711f6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mlflow@sha256:ecec84d3b5a5379b10b6765221fd8765c93e3ce0d72dcf255015b81ac638dbd6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mlflow@sha256:46b62be67de90a468b3505276f47125431f2bd45f41c4d26a093635fe4bb6584
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mlflow@sha256:10605ab34e356acfa87bbc72d79159ba4002c3e319663dd11c20805255860bbc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mlflow@sha256:cb439beb49a3ba27ae5d88bc4149273ac14aa73e94ffa0557b2314e268794f3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mlflow@sha256:48fc5e68214b21d74ea0a9de0e53536f33e207fcdd3a0e8c6f6ceeb609f6ee78
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mlflow@sha256:4aa437dd779995e3256cd2115711aa640bf53e2d296edce6778845f68225bc44
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mlflow@sha256:080067ecb20b5ee176d14a4566b520aa9f40e07e625f1e722d6d5011d0d33658
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mlflow@sha256:7b04cca7859f244957c950d2baa3cbaa89259efe8ba42d1ba8f0fd01ea1dabeb