dhi.io/velero-plugin-for-gcp
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.14-debian-fips-dev, 1.14-debian13-fips-dev, 1.14-fips-dev, 1.14.3-debian-fips-dev, 1.14.3-debian13-fips-dev, 1.14.3-fips-dev
sha256:e0a41e1cc09fb067604b81ce5630577624572bb2ab4de01ff3d439e0e7702fcc
Manifest digest:sha256:5da920c1586843a0ea151a7c7bc75ebd51dbacddf1fdc4950ce40d1c228b3d1a
Size
42.15 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/velero-plugin-for-gcp:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/velero-plugin-for-gcp:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/velero-plugin-for-gcp@sha256:cebb5383419b62dd1c2991632f492aae4dd18f13544388de55a27d5263c9e7b1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:630df59a26d80148e462ad76b42f2c84927215a36f1382cc12b8bb3a8f21dc6d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:54510e760c5c49fe916453e430af2c089099e32eeb566687086443e03c9ea423 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:55c1fa05ea8c93fc98b5a6a626754d7d6be413fc847e41c19c629d1dec6eb178 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:54f1231d77a05d4b03d592ea462a95cb912afc4084ec7dfb45c25dee1e171fc7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/velero-plugin-for-gcp@sha256:765d2d260cc4ea1cb4ff1cced2692a915c0b7913e47c9c572c4b54d5c8f5fbd8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/velero-plugin-for-gcp@sha256:25bfd9d57434cba80777025e2916f868ea3956355b2311e69e62efd95f05233a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:d765c29e4c79c76ed4fe6e618107f165169b8fad61de7eb8e32e58eeacf0c65b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:7f2703924cae753dcfe9bd0fcaba49821fcb5064919a5aa6f01ff459a1903c58 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:8cd25277a67e55cac55c57033b25087b091ea16d9c0937e1eef50e793ee8653c |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:163b07c0d84666a609d420709f86768d67c1b2128a6565e581385571f68dea68 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:6e3692a61d879c1540a6f0c2a4057748d444939a3cc5f9c42628d2389108187c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/velero-plugin-for-gcp@sha256:d064756959afe7f449223d1c711a6f23484988d8cbe24e393916a7dcd496b179 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/velero-plugin-for-gcp@sha256:c7d3120ac59497d6230508726ad19daaaeec0f05ae254aba3ff11789ae84ec7c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/velero-plugin-for-gcp@sha256:99b1cf7251a631300a3a551dd0451f167fa536e20c3c46ce80f36f0e0889c231 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/velero-plugin-for-gcp@sha256:1f84624397dc08a30e12ad8fd0fce39a50c85c6ca3a09a6ee2aa23a2b0df356e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/velero-plugin-for-gcp@sha256:f8faccdc41951f12f1b0abbca242db7a8feee63d42c293d0f95168c412c0390f |