dhi.io/nvflare
2-debian-dev, 2-debian13-dev, 2-dev, 2.9-debian-dev, 2.9-debian13-dev, 2.9-dev, 2.9.0-debian-dev, 2.9.0-debian13-dev, 2.9.0-dev
sha256:10e9e88f37271779db39fa0dcac1ce18c3e68f7927d138eb4984c2e883097232
Manifest digest:sha256:191e1a156f44fc85f809d14855ae19c457e96415901506efc1683de66434b0ff
Size
67.32 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nvflare:2-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nvflare:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nvflare@sha256:43f49b6191e98f04183a29e996c5df50990adcc7973af098d1e3e1011441109d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nvflare@sha256:5384b5ee359f654f000a1ceff98ecafb3ccaf0eccbb7043d1f5b669fc61c23f1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nvflare@sha256:f676e4b51abd1759077b7f0c399a940e55d60b892b5b0ce093dde4792566e575 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nvflare@sha256:7a096841bc07c962d7dd7ee8e003b4e5ee41a5d7218f0996c8da19846f7495ae |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/nvflare@sha256:3b124e915fa7e08afd66b1f770f0e5bd54585ea556431651c6e0a8dc267e6d96 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nvflare@sha256:4a92f779611872fb2e019a6350435df731b1808d4d61281b2102528887e032d2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nvflare@sha256:985826f3937f4ca15869cbbbe5ed3f5eee2f420cd06af7ff2f7e6e8f43edfed2 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nvflare@sha256:eb51ea20e47c7dfdb7a731f602746743a76f3e8198bb59cfbf6f7a30c929bc36 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nvflare@sha256:2351ff9d58fb3c2bbe27f900d1525f6087003f46faf14f80c72866fc88e2a91f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nvflare@sha256:054e4390c26ebfc2d818a2295e8136a3e3504eb2ca3f83fafc3eb232eb221032 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nvflare@sha256:fb181466cf6e6141be15ec817666accf9097d1dde8ef03ba45a3f9338832e23d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nvflare@sha256:fd058f9702ebed639c9b6ec4d3d6b894ea1f5d7723e815ec7f6595a930f003fb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nvflare@sha256:cc2b63c90d778b9fe508400591485041003cdc5fbf2841e39c094c45c48c3260 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/nvflare@sha256:3f7eb8060acf16b9ac5297c1753a290d864e09c7de7ffebfaf05eab5ec720b21 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nvflare@sha256:a5b51f4013e3025c1041c44c0d2f1ecd7ec20ff940aea74c000e279ff6885779 |