Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.12.x

CIS
linux/amd64
debian 13
Tags:

1.12, 1.12-debian, 1.12-debian13, 1.12.14, 1.12.14-debian, 1.12.14-debian13

Index digest:

sha256:fd7c02ceaa159d095bb1f79a4effe5ba8c6f36ee568f68d18150a5134ca81997

Manifest digest:

sha256:e6dc88b103ff9dfdb728f59ae8375c040695c6fcd617880510e3d4290fa5bf7d

Size

370.00 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1.12

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1.12 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:9e38a3a2f4d3d80c86efc02449434640e40933ed71d1722b0467b1b909ea8a8b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:cf1046b2da84d1efd8626e017749a57d104e19013a91afb355b6a61a589cb80d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:9ebb8155f0694e50ee62ed2ba51dab02025ea7ecaacfd03b2cab75ef186b5269
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:59b5d136da641b8349e2352f5afb226a3e1ba7fdce8ceb0e28dea7ae8d0b59a4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openmetadata@sha256:90aeac42150b05503a322b638b48ad16d24148fc83c3b164c07d944e6160323a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:19fc125af56ec7ee5d87fe93ebb6da7d3334615c40cfb85d235c0b996c5d8838
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:38c57a2a7e05a9b4ebdc5d9c3ecbfeca6a1b34f0f94bb7d3196bd7a629d396fd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:f3b5076bfa9d0a3e869cf1f9a22821e1dea66fd4d8a22e0aa67134b7e8f71a7f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:3b28a8c88b8a77425a9410d5f17ace46d4aeb49d602f1d9ed60b4b414a5e2d4a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:1fa3da62c9e1da3fad84c2bc6efceacc311be6c186de1a1293c44adb0323ad5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:fca71bc3082dc07c51f241631891ed30827318e6b478554e1634daf24a6a7aa8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:70069a8ab6cd4305ea47f74a786d6ea3587731886fdceb02f6e080c35391c4f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:0909ed5ba67f8ab84c279781a48ba8a9127c9b26063d12d08a9540b4652b5766
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:e5b9c40a11a9b2e1dde05d98e56834a1d5721d7f203e3a378ef2603e9bf479e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:8f263e0e6aaf4ed5dbe28ce2bcc99e5ab5046259d79b54491d9b737297959a7c