Sign inSign up
trust-manager

dhi.io/trust-manager

Trust Manager 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.25, 0.25-debian, 0.25-debian13, 0.25.0, 0.25.0-debian, 0.25.0-debian13

Index digest:

sha256:efb06dda8d1a84572e9995697fa855cf7fc6b3846434bc339597967f7fb5c105

Manifest digest:

sha256:fdd51f46a6bcfb7d76ec07301f786994dec2bd0a41c10da3d28b05aeee3b6b14

Size

10.35 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/trust-manager:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/trust-manager:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/trust-manager@sha256:f22809072ca2e698d386f404c49f8acd458f812b569f18f59188180101946296
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/trust-manager@sha256:643d400da85f44fa95a5061ed1e6d03060862f0761f62cfcaf1053f95ef6ccbd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/trust-manager@sha256:93c3e8c584e9961f5a432135ad08813015d45074c9bb790f9153c8c8077f238c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/trust-manager@sha256:820c52526d1f31978dc7dbc349567cebd334c59846c00e32647aa94fd3a22bda
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/trust-manager@sha256:6640bee6023e081c2b1d4535f9279562123ec44d6b408a1591c7426e2b003ae3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/trust-manager@sha256:977013189366cbfee5502120f2fee90e3791f12c7f465410bca14986f304a7ff
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/trust-manager@sha256:d8bcd8191fbe34822aa33e39cd4e368bba943566e972753a498e6af9b9ae4856
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/trust-manager@sha256:9e79d07d2fe5f4588c0881d9eb8cd50d81a8cedf2ec8aa3ace8c9878694653de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/trust-manager@sha256:6fe4ac60b2245212fd390cb5ada6ca13227585a9adc36bb9b1d4a5f746ae43b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/trust-manager@sha256:5101420e169e8b79db3c2df782365fc1ff35b3e17cba09b1efc0893c2beeef19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/trust-manager@sha256:04e05ebaad1b00cab13f7f7497bd27417e99465c8845f180b5e8c447dd488cba
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/trust-manager@sha256:9897573c28a97ebb600a27bb000c63ec027a57a535bbe472757d3c648234beac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/trust-manager@sha256:1423a153e7ca66417d15b25cdd75a3173de4dde8d37e59a959cc54a32bd7798e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/trust-manager@sha256:7ed4da0bd0e6ce603da9d5a3d08a6d12291206d77a160780b1dca0d486e951a0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/trust-manager@sha256:b2790d0f9a5486379c50ebeab49f8534e3246f5bfa98a29019db285388270315