Sign inSign up
NetBox

dhi.io/netbox

NetBox 4.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.1-debian-fips, 4.7.1-debian13-fips, 4.7.1-fips

Index digest:

sha256:e44588db59a3c14c377c3e216f24002b0ac9b99302c05db7b1bcf57c9049ba10

Manifest digest:

sha256:6878ee68ab81290100bb152220b8a4f5ed23260aca4c919e95f185fabed6809c

Size

118.69 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/netbox:4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/netbox:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/netbox@sha256:8036a06cd72882fee26881cf4d7d48b4c491112f1fccfdcfa1ffebe05e72c2fb
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/netbox@sha256:b61eb743923ee67b98bec6e81267e58599f851560d3514e1e3ffca4a3a9f8a0d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/netbox@sha256:07388c08afe4279d8f3b48a38308371ae01ed2329649c0be662ebdf48cc4a526
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/netbox@sha256:70b9e35b966c129c2ff2646e4a57387a9350438a2ac44dc8023c0f1736244049
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/netbox@sha256:16aa901d2782ea6910c8812556987091c7f09f21440e969bade778dc1505e78b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/netbox@sha256:b6a993b870962d8aa28aa8262cd9cfcb5b9853caadd1d14ea51435865160e0dc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/netbox@sha256:cd4b3dbd41b1e44a7a6a14fea775738b1368dda6def367b30412351d43768644
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/netbox@sha256:d97027c02dd62c11963a7ed992425837273ce7a3ce54c9948ed04dbdc44068e1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/netbox@sha256:73c2d0a4f798a285e7bdc354e0fbc0072277410b9aa48fc939a82b7747b4c008
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/netbox@sha256:7bc696a63cef0bc10899fa742c7ca9e7a467f71a27d945e659d70ef310f1dd55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/netbox@sha256:27dc3cbb4199bc58faf33441940caad935235e3724541ebe1625474b873262f6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/netbox@sha256:e320a32c93ae599554ceebd7fc169c9e0a1706a69b4a2bd311fa45b504b508e8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/netbox@sha256:413b3a88c1ebe0a7d5bdac8e1eaa03b9c7f43f7b44d4644565e342f88ca970e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/netbox@sha256:711edf2c266ac4d9f33c068f9404181862e90446005ff1d70a494edecaac6785
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/netbox@sha256:80db10a93e2f06145bcc930b140395f4a2ffce7c673d33a5ab8a4336c14e65b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/netbox@sha256:f4cbc77777d3b3ffbbcd3112615966b6a493c49d4066f340c7562d25b8aeebc0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/netbox@sha256:4f2e5341d147a82d36d0785fe9b4ed0e753a2e71b6b993cb6d8f908346d0fa9e