Sign inSign up
Zot

dhi.io/zot

Zot 2.x (ui, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-ui-fips, 2-debian13-ui-fips, 2-ui-fips, 2.1-debian-ui-fips, 2.1-debian13-ui-fips, 2.1-ui-fips, 2.1.20-debian-ui-fips, 2.1.20-debian13-ui-fips, 2.1.20-ui-fips

Index digest:

sha256:62215bd7aff5c6e0c59cc7f538f811a526c8f98b3329482bac70b3ca8ea486bb

Manifest digest:

sha256:502cb139cef68ab07ab710a0a3d829e9551e891919c031d09342ac9984ff19af

Size

58.34 MB

Last pushed

3 days ago

Vulnerabilities

0
2
2
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-ui-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-ui-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:755bb335c474ca23fdd0abb063282084175b4e9d74d2590c66c181bf98d16bda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:367f75fd24685195be2a384eb077b1a2944e810d340de0cc574e74b03f9170fd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/zot@sha256:a088397144a749d0574059a98afce9616e81214636ba11a4c2b202059ee38fe9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:ee624e924572627cd22290a36a4727a0783a3e8be9d4095fbb07cb3cd5380156
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/zot@sha256:df4c2857fe34a2751264cc902443d1c9240b62fa8ef06c887112c6f6671c6d0a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:d76af77b949e9f5d895a17fcf1b6a4be72847cc3614998e7db969d5e7dc73298
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:26083610227067c8cda5523893f44986a5493f06264598ab161eea299e292556
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:7ecce733e9f6d41dcbef8667494a2669bdc778978f1c4f09e2ec7da6eba36719
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:15a6267d5bf9d9ed74f79c566d3b0d9ec6478e3dd30d26e38b7219488898916b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:18158da059b1aedbe04a56ea36553b76ca09e009dcfdd9ffd511f6f8ca57dbc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:298b9194051d54caad7884592e8dceffc1b3111e122647d4734955359f6d664e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:cf257a2614d0cfbb54a75d9e76cc37e8aba1f3b7e79141141411e5587ac1104a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:14acd5f6abcf249f2b39b667c0a96e281f8b7e9c6229ee97c0b350c32a07d9a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:297895c3db7dd168d0e7d102f2788fc1e27fe1a190582e9f4040daabde78d5d5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:72234e4690c9031c66ba4532a702d3e5d7ff311381c0cf676d9bffde4c51af02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:6ba88d798e2d297950e55ef420cdae68db22eed05ce84dedab36b986723e52af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:5ea6e5a07c87914ba15c482c98746a8c9f303c58c0528d88ff623c953f8d34b4