Sign inSign up
Airflow

dhi.io/airflow

Airflow 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3-python3.13-debian-dev, 3-python3.13-debian13-dev, 3-python3.13-dev, 3.3-debian-dev, 3.3-debian13-dev, 3.3-dev, 3.3-python3.13-debian-dev, 3.3-python3.13-debian13-dev, 3.3-python3.13-dev, 3.3.1-debian-dev, 3.3.1-debian13-dev, 3.3.1-dev, 3.3.1-python3.13-debian-dev, 3.3.1-python3.13-debian13-dev, 3.3.1-python3.13-dev

Index digest:

sha256:5544badc9bc8ddcfba3c1e0d60c612a194cc13d35860bd43c0255a7393f2aa71

Manifest digest:

sha256:52969bac2213b25c6fd31800f656bb619e56f30da4a576a5e5aafe4f882daec4

Size

78.22 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/airflow:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/airflow:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/airflow@sha256:f899c273b038b0744ba72ad2b6e8477bdb01d2d4f97e333e52684b4d8feff459
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/airflow@sha256:3a3c652cf6dc2020b2b8e94293b348b8ecbbdd679ea4ecb360bf81fa464d7e0b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/airflow@sha256:794a346015add3fa0bc8d733b5f1b4ce77cbc3b5a57dfbdd96d5a74836b57b3d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/airflow@sha256:def01cd8c4925bf25faf001060fe447cf5245d9ed35f435cf455f7d7194f7eb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/airflow@sha256:4ee11dcff1db145443ced309d068f48c230033a12ef27084e4bede6dcc87e2bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/airflow@sha256:331f1857e413c593664fb40bc4d19a65fbab57669682efdb453e5c51aa4e93c1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/airflow@sha256:9c0da24bab33e13b0be7b180ebebaa9924a1d8f1b964a645b4662984be9074d8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/airflow@sha256:78093cd975ddd7ad8c95c847915f268ed7e8c5e05899917fc2c703ca0be1f06c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/airflow@sha256:f688132727c4e1d78842246f4c21193ac7ed27152df831b0774bd0d99155f453
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/airflow@sha256:b5dd41b4b8e03d272d91fd9528428e2687e42f97c8cc043b94030933a6a3343e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/airflow@sha256:e9fc3c697f5059a3d11d3a6ae1a66ba201ab452928e2eaf0258bdcd35dc36d0e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/airflow@sha256:83f24a88d2986a2ec8386047797a22423bf3027eadbf4d9b83244df925e26eee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/airflow@sha256:f31ebd59d1c635489ea70d3cbef13a0d6d2c501ca623559e6be74ce995941428
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/airflow@sha256:a8832156fcd33ef5b35863fb2b28df82ccd9f5860ced7a80d15c3ec79018b4cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/airflow@sha256:b8c6ccef5d39dc124411eed743913d3dd6dcf700b091bb47dc6f8dc06d648ea2