dhi.io/openmetadata
1-debian-fips, 1-debian13-fips, 1-fips, 1.13-debian-fips, 1.13-debian13-fips, 1.13-fips, 1.13.5-debian-fips, 1.13.5-debian13-fips, 1.13.5-fips
sha256:5f6779467ea3819543a2697064108d105b72f749937b687b2a044af6a3ef9b8d
Manifest digest:sha256:1e4bb2c5cf09e7cd80e853dd4e638c46541a080bfa1b06459ef091031f19d927
Size
398.81 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openmetadata:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openmetadata:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openmetadata@sha256:0e96718ff109dff80b14205f88280bc37a5b7b1b0fc97320872cd6ebaa404509 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openmetadata@sha256:bb7312f6292550303d5eaf86afc1d685e2f0ff2a04ba9e0d2e033039ac6f81bf |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/openmetadata@sha256:790d38ccf5ab82a786507c9502abba68df178ecfd30554bc30f701e307f225d6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openmetadata@sha256:af21e2c5555db7d68b39ca91dc6c840cf863026e7a1707e1abcee528cd523a38 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/openmetadata@sha256:0d805d4950470fb0c63f04c06702c6959cbcfd6ac1b62043eb338fa8ca69b78e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openmetadata@sha256:bad4084acc702d4b876ddfd86082caf4cde5b4f14504cfe6ef6388f30b39506e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/openmetadata@sha256:a7312765e72c5b88e846d647b88a0d9d506d51cfee55733c6979d8f44b68e62f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openmetadata@sha256:151ed8c96dd7ce589d8d9c7d85f1df749502a653ddb5c45d9f6931b016c5e17f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openmetadata@sha256:06fda84f8c991487fddf2e572cdf3e1338f18dd8e52fecbda0a9c1e5fb6d5323 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openmetadata@sha256:7099a4a705b469bec5795b93699bdf32092c34fa431840fd01dea2affda5ba4c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openmetadata@sha256:ab7b4848b10c993e0522dace9ba38f7bb8d0b16a9bd2496e84cf851e33c54bf0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openmetadata@sha256:bdc20ecb226d23c5ebe1ad7ad729e62daf7c939e14bb4007873c63c61229c45e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openmetadata@sha256:622fbbd7c0c6b946fb18ebd494067d8529d855a438fb1069d2f7f58c75688090 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openmetadata@sha256:14aa83c7cf4b90ee7045620826b752f2040acd3b5c8e58a2a83ceeedecb126b8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openmetadata@sha256:b286f04a213d86ba250ec5160b74213f1b5779d0dff07e64ce67643c985080bc |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openmetadata@sha256:990a744805d1f2c14aa63e9725b043f970b8412c268457c9602bd33db80f184f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openmetadata@sha256:432734d4b28d7e5c74444f24aa26d2a4297cc9d259090f0f5283c9f51d9f2b68 |