Sign inSign up
Velero

dhi.io/velero

Velero 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.18-debian-fips, 1.18-debian13-fips, 1.18-fips, 1.18.2-debian-fips, 1.18.2-debian13-fips, 1.18.2-fips

Index digest:

sha256:043482246ef6d5efb6eae8825c4b3941f0238f9ef158b3dd15e8cc5b3901d093

Manifest digest:

sha256:e67144775277b06f07ba2b3163a523ad6dfdff019392b2ee87b137db95ec98a2

Size

48.26 MB

Last pushed

7 days ago

Vulnerabilities

1
4
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/velero:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/velero:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/velero@sha256:239d523fb317e50cb6a8dd09c49fc1a987631e3489c3e973e0e1a5ddb73f9417
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/velero@sha256:6a81070933414eb16024b9001077463f1c19d1ae5fae99d494f4254b810d2dc5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/velero@sha256:f103257b6edb6a1ae59d73582c62b10d7f014570e47c93a09755827406c4b0db
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/velero@sha256:12a137e67000096fb2bbc5d927b0a190f52619ec4daab53d48963bb66520817c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/velero@sha256:981cc9b953b45cb317d7d566b6e712b376f15c26bfa7f2900b5a1dee860072be
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/velero@sha256:e6cfc960412b7163a1b26e6ae14899624f6ba9ce9422bd85b333af7073f85d7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/velero@sha256:80da82d2178d74b8f5a313d39f232d5cacd07413b4019c21bd39a2d24da15c4d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/velero@sha256:43a6db820461b6c0636973cdd47aa1f33a7996a981f07e919024b6b453f1be80
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/velero@sha256:5fd9f8528211af8ca442e27f6d0dc994f8da1650dedc33263973a424976486ff
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/velero@sha256:22e84923083f4d4a065dac386b613a2b34251cb800590bfcff61ad1029fda3c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/velero@sha256:bb059fc3207bc102970e5af10a1c46c3db19c889752e603f49765d14b78d41a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/velero@sha256:8cb79372986e3c69fc2425807a8160454698dfe0274a7fad72efb733f58c390e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/velero@sha256:e8af97c0b0b81b7ab0b706e9ea064a768787cbafc01ac59bce5fa63f52eb02b6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/velero@sha256:e000368c5af909f9d39ed16e1fc9e135e8c428eae7f619883c0281ab7ae0edf8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/velero@sha256:2a4a603214bae66511094bc89c11615a42274b797797129e9780c9651fe290dd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/velero@sha256:42b62a887999a15df267d6afd8927371c1c25da6b026db3b1fa58171537e4fc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/velero@sha256:c3494fc54cc4f0be110aa6cf6a4d9a466be8dee59cda8a8383a6a0fa8c32b0e6