Sign inSign up
MLflow

dhi.io/mlflow

MLflow 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.16-debian-fips, 3.16-debian13-fips, 3.16-fips, 3.16.1-debian-fips, 3.16.1-debian13-fips, 3.16.1-fips

Index digest:

sha256:5f01b86215644b9b125aea6c9c5f8fe1d975c355d96479eeb7296344556d5a82

Manifest digest:

sha256:76503c9265a6b778429de6d0e1c2c4c2c93c970c89d19e6b48f81cfb1ba91e7e

Size

152.65 MB

Last pushed

60 minutes ago

Vulnerabilities

0
0
3
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/mlflow:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/mlflow:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/mlflow@sha256:8544c2edf664dca9953a9a219e5db4964ae3cdf257165df57fcdeb4655d2f4c0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/mlflow@sha256:132944f2563425fae0d34d08d102beb3ef8164df2d1f1be8150db96ac1dcb5b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/mlflow@sha256:069403ac1be168d48f5cc91951a9bc17db57d05b047dacf235c3169998a575fd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/mlflow@sha256:04725dced0bde90cf05ec5e256da912fa0efffa6c09dbff5d08730cee83cf95b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/mlflow@sha256:96e497cdda53e88098d9648faa0bd4a6161c8657bac58e3838613aff995fe426
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/mlflow@sha256:8c4b651f77574e6844b0f2eb7a9e84fbddc40cbc4702c5b5168f01911faa0137
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/mlflow@sha256:fcd05cd2ab97932a72c4e24e3491bc42cff7882c9a34a5a91c9e758626a3fe00
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/mlflow@sha256:82cd023533e8ba53a658ac692bf6f44ebfc4a36ed5784ac7497a62cf72810b1c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/mlflow@sha256:7ac4c066ceecc69ce85aae356b6ead031b3834a98556fee4af1a9351ab412cf1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/mlflow@sha256:e9ca5960630465ea34682fbea69b2e618ec658a6f473d34cae95cc9c1ce28c3b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/mlflow@sha256:a031ca0b396fc935b57655fd6b850fca827d92f33bb110dc7a33c845654ee934
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/mlflow@sha256:1f85e7a2acb480cc53050555474205194a341daf23181d772ef16878ab54c24e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/mlflow@sha256:b2a3e27a5740c13438aa0df246876bac45095d914bc9d7ff4a2747534dccf4a7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/mlflow@sha256:0d9046c84a471634a3f05ecb39dae9f7364b4690ddd39c5b88fd62801d8597f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/mlflow@sha256:ddc44121eccc407cc6ff31ab38c6de7817a6810369b37c3f12f0bfb2f75b2e35
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/mlflow@sha256:4f8e0dee28486154353d2409bfb1338b0a6b44fd85f0fa1c1f2728b7180c77db
SPDX SBOMhttps://spdx.dev/Documentdhi.io/mlflow@sha256:38ad638006a23f693d26175157393a70c10f6be1a6729007ffd78c33c4672aa1