dhi.io/openmetadata
1.12-alpine-dev, 1.12-alpine3.24-dev, 1.12.14-alpine-dev, 1.12.14-alpine3.24-dev
sha256:3c52e6b8756bdecd7efc10ac01d3bc87d29f7d79f9c6cd68b72be0a3b53dd87b
Manifest digest:sha256:a3d67e8ad06d6d9655a22ba45ac8ad5d730ec250b9caffa2d830ad0a99808c58
Size
363.57 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openmetadata:1.12-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openmetadata:1.12-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openmetadata@sha256:f4efd1ea6a8c61528c90a6d00da28d0e7a877e052ad000f39dbf7c753f82c570 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openmetadata@sha256:105f822fd5539860707fa7b698f5828c8f1699ebdef94e405dba232ad9411012 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openmetadata@sha256:fcf26928de267bf8af516c9086ef8d8dd68b08bfb3eb3d57a39a6f86dcd79137 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openmetadata@sha256:6fc00961e0b252995b7a743323ff9f5f44202f01ab751c4d81aeba7acac7c2d9 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openmetadata@sha256:696e0e209598bd4866b2b5656926e631f6536af78ae9b7cf3c54fa3d57fe0c1c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openmetadata@sha256:6667c9fc9a5fb47986c12320d8185507d537eee1f583f6e72e7cce5177711099 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openmetadata@sha256:88d3fa92ee7a9c3b2414e8e4d56ecd5c154bd428eba00fc96f3a4b764f75a218 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openmetadata@sha256:032c4fe8ab8ee78bfd54c52741116830d28e2a36e5aea38d3d829d6780e2940c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openmetadata@sha256:bf1564f933a07780683eab156a9bae0bdd1a6a609cea12c691eaf9cb7fd9e813 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openmetadata@sha256:e584b7e542f4a76d69b4d8d412e9e4b72f78b8be885d3201c16cc63b6315d3a7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openmetadata@sha256:1ee8d606100a94407e52e7bc3deb484eaa065807dc7bf1f93166e63bdb7b2a1d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openmetadata@sha256:92ad5e357b2505e6737b9fb9572fc89deb2ed0f19af868f40e36eb0ac9428cbc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openmetadata@sha256:215c5614192bdbe024f6fc4f8e9221338d203025f1bfce78d7b7f09c0c6d3755 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openmetadata@sha256:fc07fe5f724d261ddfa66db2a7962231099dcebfc97a383025bccaa85ba8ad57 |