Sign inSign up
Zot

dhi.io/zot

Zot 2.x (ui, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-ui-fips-dev, 2-debian13-ui-fips-dev, 2-ui-fips-dev, 2.1-debian-ui-fips-dev, 2.1-debian13-ui-fips-dev, 2.1-ui-fips-dev, 2.1.20-debian-ui-fips-dev, 2.1.20-debian13-ui-fips-dev, 2.1.20-ui-fips-dev

Index digest:

sha256:ccf2648222172420ac27e5d947da43fc20b0e678cef89b8a3c90218b2aed0130

Manifest digest:

sha256:64270f282a970d63df83c4692e8cf6cc706f5c42ca6670b0ad8d8e9fcbf1671f

Size

73.40 MB

Last pushed

2 days ago

Vulnerabilities

0
2
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-ui-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-ui-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:1e33f082b0744de28434405acb38dc957aea14f278136531526bec7933a545ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:30c08563212c83f92ec309ed24af7315121c3eaaba520414de658a4f7d1765fb
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/zot@sha256:2fe593866b50eb52e518c29e40e4f11310da72767cce5ee9cf8d098b82a8dbb7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:133b7d87f74248707e3c4dc623ccf668df4bd7b1271fbe42bfb769bc4c2a4656
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/zot@sha256:14f2069df5b7478168aba8e70e237de74e3c4e8b73b3aac12307e779fb86dc6f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:7e2a2970dbb97f16e966aff6ced88d26ac60b09309510482977a1c2351342980
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:9be4ab0ecb53741d196b5925b78e318e996d46cbf5eff66247cca41ee4f9b5c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:c64a78d015dcd73cf1b4f2ab528f3dab7383769ac084ce0b2ffd5f0ceee238f8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:c5dc4e8ae9725ca5c48fc18efd72b3e196c552010862896b5f16ca349af23103
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:8c14be6517631385d0c58f6749eb785120002d1f6824ade215fe6b89467174c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:6171634311ac93fa605a1b4ce992318040839e8c691027aadccb244ea0129ccb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:213aa2a93188000dc576e30ba95fa98baa0e4ca4e6a66564ee95fb8d6e8a3ffe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:9dffb082e8ec829cf8468c949095cd5df2144ee191d7e2945b220e9f594ad3db
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:7da1e78453ccdab826d6029c8c79a5c2170f68bcc01aef8f4656867d34bb829c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:68ff7516047aef07a47861dab03dbc1caecfd509c472ec95f6dc97ac2d268d72
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:7ece11a517dbdf9b49229e21ccb61183386d7d33d15e316e9e1b6a47fcee1745
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:c60c64ef051d568a5823691ff44738285f9283cae8204b5579fdf2aa1e4026b2