dhi.io/ovirt-populator
2-debian-fips, 2-debian13-fips, 2-fips, 2.12-debian-fips, 2.12-debian13-fips, 2.12-fips, 2.12.9-debian-fips, 2.12.9-debian13-fips, 2.12.9-fips
sha256:9a566d4eb4f4e76bbc2b53c36a19ebe64e34d92deacfc756a513bbfe055fe99f
Manifest digest:sha256:8c71f13f040fb2862d9788f0e93dd21f24bc5566f49090374f9cae0696c5a7ef
Size
32.86 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/ovirt-populator:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/ovirt-populator:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/ovirt-populator@sha256:0d763b77278b787bd8784b13c4f5cf197f00db38448b4a5043bb10df7ebd4216 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/ovirt-populator@sha256:d448544a453fcd7e1c75f09fbd37418137d43888b991f33c722b1050687ee3a1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/ovirt-populator@sha256:5cae104324179d2dddb345b668271122e729a2a8773f2b8d9373766ce644bcc4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/ovirt-populator@sha256:e5d54fdc49c37a09cb1ab9a88375abee326c2e1b8854d4f6e923c5b327142138 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/ovirt-populator@sha256:2e415e86c331163fb14e494ce211954fa0e1d278d844eb9a6bb79868de0d160d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/ovirt-populator@sha256:7fc40db93fca61ee78373b5c5c4e4ca434ab6a7befc6e0ff2ee8fb65990024fe |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/ovirt-populator@sha256:a89c8ded8b22aef750901c6523558572f195599b9ada0a3b85ebf7e056dfb5c7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/ovirt-populator@sha256:2f58ff320cf978c0545ad82ec4f1b6ce110049b5fe55e1ac63844ab332bea9f9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/ovirt-populator@sha256:f181ecd79ecd2e173b8ecb1f507fdf2eaaa844c2cd635f1ac8f563fc6e2afc94 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/ovirt-populator@sha256:4c013c263203d49014f4d1a4bb003316a90ac2cc7cbc9ec358c3e4c9fa139143 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/ovirt-populator@sha256:73d910a084e60af525ef080e12ab23fc552c17258bf8a4cc034c7bf689bdd18c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/ovirt-populator@sha256:ebef88c3bf12f4efaa8d0424ab651636f0d3a0a319df16049da999c28360e409 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/ovirt-populator@sha256:c8d72b4f6f99ddf11db2816c1e5ec0519c301a4beb8cf7044268293865c1d8ff |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/ovirt-populator@sha256:a55ed1073765c72ce37db0392a78044edea048a43ec13db098ae3f01fd9e825d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/ovirt-populator@sha256:60691ff937cc75d3e54e233369a35619bcf14385b867003d4403bee0b2a474dd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/ovirt-populator@sha256:fcd3270547299ab9d02bf54bc0e5c46bec8042ea1e891e5dda6065bda7309609 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/ovirt-populator@sha256:7eb4f6d1abea29e9910d5b9bebee9504d797bf45870fe8bd4c749c7703da8472 |