dhi.io/zot
2-debian-ui-fips-dev, 2-debian13-ui-fips-dev, 2-ui-fips-dev, 2.1-debian-ui-fips-dev, 2.1-debian13-ui-fips-dev, 2.1-ui-fips-dev, 2.1.20-debian-ui-fips-dev, 2.1.20-debian13-ui-fips-dev, 2.1.20-ui-fips-dev
sha256:ccf2648222172420ac27e5d947da43fc20b0e678cef89b8a3c90218b2aed0130
Manifest digest:sha256:64270f282a970d63df83c4692e8cf6cc706f5c42ca6670b0ad8d8e9fcbf1671f
Size
73.40 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/zot:2-debian-ui-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/zot:2-debian-ui-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/zot@sha256:1e33f082b0744de28434405acb38dc957aea14f278136531526bec7933a545ea |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/zot@sha256:30c08563212c83f92ec309ed24af7315121c3eaaba520414de658a4f7d1765fb |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/zot@sha256:2fe593866b50eb52e518c29e40e4f11310da72767cce5ee9cf8d098b82a8dbb7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/zot@sha256:133b7d87f74248707e3c4dc623ccf668df4bd7b1271fbe42bfb769bc4c2a4656 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/zot@sha256:14f2069df5b7478168aba8e70e237de74e3c4e8b73b3aac12307e779fb86dc6f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/zot@sha256:7e2a2970dbb97f16e966aff6ced88d26ac60b09309510482977a1c2351342980 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/zot@sha256:9be4ab0ecb53741d196b5925b78e318e996d46cbf5eff66247cca41ee4f9b5c8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/zot@sha256:c64a78d015dcd73cf1b4f2ab528f3dab7383769ac084ce0b2ffd5f0ceee238f8 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/zot@sha256:c5dc4e8ae9725ca5c48fc18efd72b3e196c552010862896b5f16ca349af23103 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/zot@sha256:8c14be6517631385d0c58f6749eb785120002d1f6824ade215fe6b89467174c5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/zot@sha256:6171634311ac93fa605a1b4ce992318040839e8c691027aadccb244ea0129ccb |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/zot@sha256:213aa2a93188000dc576e30ba95fa98baa0e4ca4e6a66564ee95fb8d6e8a3ffe |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/zot@sha256:9dffb082e8ec829cf8468c949095cd5df2144ee191d7e2945b220e9f594ad3db |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/zot@sha256:7da1e78453ccdab826d6029c8c79a5c2170f68bcc01aef8f4656867d34bb829c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/zot@sha256:68ff7516047aef07a47861dab03dbc1caecfd509c472ec95f6dc97ac2d268d72 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/zot@sha256:7ece11a517dbdf9b49229e21ccb61183386d7d33d15e316e9e1b6a47fcee1745 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/zot@sha256:c60c64ef051d568a5823691ff44738285f9283cae8204b5579fdf2aa1e4026b2 |