dhi.io/virt-operator
1-debian-fips, 1-debian13-fips, 1-fips, 1.9-debian-fips, 1.9-debian13-fips, 1.9-fips, 1.9.0-debian-fips, 1.9.0-debian13-fips, 1.9.0-fips
sha256:804ef047d663cd15468eb479b02d79660f67faf5bd7ee3eb9786f9bb8d072c68
Manifest digest:sha256:41010471afe14e5a5351ce228c08d8bc658ce267b4063862b052c1925bec1ded
Size
25.63 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-operator:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-operator@sha256:cf5712e339293e7c668b42d0cb91e344fa3595657ecf7933e686744a6d3534e4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-operator@sha256:5533df4a8f0ba1765d1796c73ea1935d9b75f3b55ec3b0d44b9bb68d7d6d7b0e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-operator@sha256:de7e23295326b5d9170c3869f1fbddea08a92a262471284abfff394bb30beee2 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-operator@sha256:c95308dbe46984801bcc5188f8e0d535ade40344a97bff80279c633af6c298d4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-operator@sha256:3915d5fb3f0db9960f93f5b538fd741d61bd0957e36e9834d607f316b19db2e8 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-operator@sha256:e4853189c348609fbd16fdadb08e7f53576745df0c31d5bc3d8148f2cf4970a8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-operator@sha256:53fdca1fff17b2beb650b485ef501f214b462302e90971ca0bb9cedc4bec6cef |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-operator@sha256:0c95d64caa3d724dce5c1cf2e4aaf29db40185dd275d839d3c4eaf311b723135 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-operator@sha256:792bfdfec7d646b3708249d4c147a4a8eaf40497ce37577b5cf18ca3fcd74790 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-operator@sha256:5eff404090b461400d7f4dff54ddf23b02881510ba0d831737f2d1ff007b6b96 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-operator@sha256:07e8442bf8793cbdb91dbbabe7276d66bc1142631c6d252ec6385be6743e6b0c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-operator@sha256:380dbaca95286969f6c717e2ac802547ca1b1bc79d32ecd86ddb620e8b958ef0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-operator@sha256:8c848e2e0fa3822e9a6474f04c84c63aadd8a2c5470986054460aae1de67b124 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-operator@sha256:3c864a0dc4d830006688198625fa214be6f42642aa4a7fbd583889b73845f7c1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-operator@sha256:8014f994142d7f425dcfc1c73eaebcf55b3e824c486fc1d77e9428ea519ce01e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-operator@sha256:c1a00445b203f0826579171836e7550a3bb0a1a1563a43dc73017af76c6e3a88 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-operator@sha256:75402ea8c56481c9a0c7fe5a67435ad8f0b94efe7b7986fb7d300d9cb27c656d |