dhi.io/openmetadata
1-alpine, 1-alpine3.24, 1.13-alpine, 1.13-alpine3.24, 1.13.6-alpine, 1.13.6-alpine3.24
sha256:b8aa62ff0b635ff43a0907639f9f46746706e5b9717413a324ae57504017356a
Manifest digest:sha256:0dae48bb240c6e538d2837783bcf24c19a14915f7e4da8abe62df221cfbfcdd7
Size
381.30 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openmetadata:1-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openmetadata:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openmetadata@sha256:62d7f83f867a1bd00793f9f15ecad95b02f8457813b7b12023dcbdee0f14af7f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openmetadata@sha256:d94f9798f41c5a1b7e595a2cddc39db3e9fb5d6a50a88f3c212f9bd79c793eb7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openmetadata@sha256:ec29489b2f070095649e9b1a99d689659ea171d697e072bb5e217b30ad180021 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openmetadata@sha256:9b6683e62d997e2a9c24fa6214346a9c9f323bd7597492d34715009f138c2ebf |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openmetadata@sha256:dae1c9110fca5ca00829ee2c2eb3a2a6323b4c13aa4a9b50574ba87bc17994e2 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openmetadata@sha256:e5536eb7f2c295f00e1b491eb7923dc1ffaed522ea5541271cc28d3ad91daf37 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openmetadata@sha256:57d8e1f1e6ef1cb96203c77adfcbd2fd77a2baf1a40977d90855d3d7707b9d72 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openmetadata@sha256:313fe9d14b250baf6dedda54910484a69c5d4facb5995f04c859341f5dbc8b60 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openmetadata@sha256:3b5b88b3a7c94f1c999ad21e3117158fa149815501a3a8a68563b8e64f10c541 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openmetadata@sha256:c9413ca9556e2a98efd0049fab07bf72c37301b66a9e3c916846825709798dc6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openmetadata@sha256:6ce5c48a1b4abca3f6742bf74480bf36ccbd27fb94d9fa9bc496f625d70bdf5a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openmetadata@sha256:cd2802cf3f78f7e7262ceae67065a1b40b668166007b57a4ead3067a865a8355 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openmetadata@sha256:3d0b3d33a7561fc2f51a13fdf6f18bf125ad7a402fda18b3882b2a4fbd752e1a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openmetadata@sha256:55a28cf03624a79a4e3e0b56b729145440eb4be847b27dd3ccd946bd04539e0a |