Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.13-alpine, 1.13-alpine3.24, 1.13.5-alpine, 1.13.5-alpine3.24

Index digest:

sha256:de59e3e7684bb2bd971e5b1890b03cc372e883815cf946ad35e8949c85bb8633

Manifest digest:

sha256:e5c37277551ea22210dcb53a20fd0f3dddfb673d28c6606a30b874f18381e314

Size

381.30 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:0bcf265297c07451466752a6c5b8d4b8b1af30b5c023aae1422090b825912706
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:03fdb6e214105f770f86625e50f2474398c78db14c1d7696926d5351b4525d31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:f3ef977038d4d21aee1a865ada9b9eeadc0bd44f48366b9b6270cbb52bb2fa4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:281079858f6df56b3370971f483f8e181b57efc8d52681041facf63ccb6382ab
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:9282436c444673b38e0f54b8c882b76f5617908f698a98ea84de74a70e45c0e0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:1659aa4c6940304487be2aa52e105a5367887b300eca588c3ef366cd37ac296e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:9331921f3f24defe37cc60adcb90622cd8e9972f04082d4b80b93dabc7f9f341
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:5a13a7afb64c3833d28e39927ac85a0a7dff348e8ae038fc5fda6db223591e77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:95258c9e0ebcd8c7714075f8e29e915b4ab1047b239f8aed97a4e3490a11f626
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:bad4670603a1c4a882451865febcc0b509cdf06a45c48bb3ad14bb51de606dfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:c9caf9003722aa5fd5f5bae21c08e1779c2af8b1449fdc2c83a540087b206735
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:d77e4b5946c2f20af5632f0b1f30f7b489002475dc0a114036db44a409bf59bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:b6486e29c2cc7811cf068761baa593d74e7d339c2795a845874ead956d912ff5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:a711208937d022912347c58de898eb7d0d59bc9b58dfc7804a8b92341558c7c8