Sign inSign up
Argo CD

dhi.io/argocd

ArgoCD 3.4.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.4-debian-fips, 3.4-debian13-fips, 3.4-fips, 3.4.9-debian-fips, 3.4.9-debian13-fips, 3.4.9-fips

Index digest:

sha256:0cf629b5a432cc4573e76e38eaf97c00b01223e9f489cd51295cb40b66fc89fd

Manifest digest:

sha256:3302c6285bcc4db691d7cd4f2ef4eb98d5d61ed59828280bf3a6369d813e5cda

Size

117.65 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
12
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocd:3.4-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocd:3.4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocd@sha256:f888a740b00bd7cea519d49c99d899ec83ad8edf98ff0e68a651ba6fdcdd6d1b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocd@sha256:cbd1c0eaa93e2dfab454df032f6f9a176c76e54b92e40f27becf8834bf5e58b7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/argocd@sha256:6fece6787f841c8ca5090175e23e5a08e36b363164431ae30ce86a321b157d2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocd@sha256:e352bfcb9b0ef2fccf8965812a7fd507ce3555d5d050851951f33a727cb7dd24
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/argocd@sha256:b44246b646a8c44ebafd47aea8589c95af3d2c40025465516aa755bb4848d433
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocd@sha256:a6c1c3506146fdc616fc553e0bd642938a9e46fef3c1e45d4c709f378ebcb73f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocd@sha256:6c4713ddfa8a2b1ee81c23ffe65cf30f4dd4f7525818c356e5c82b520299a78e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocd@sha256:658c9fc45f4ba33dc7ad6d6345fdfec1ce3881585c127c355bfcffe53e78757f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocd@sha256:69a73b3f0fcf0725591e5575fcc4fc343203d4e217f07c3522e7effb5a160b7e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocd@sha256:af997b287d6832211b23addbe64ab048fd72d10d8eae9240e7ffc0d8167c03d6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocd@sha256:81cf1c6544ed8c682940781e775c327b695283bfadcb4370b89c7733ab3ad040
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocd@sha256:f5ccb1c4a6d45cf375074e50d083ee21a91dc5fa95916477b638fabb8441f95e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocd@sha256:465c1e7c8c579d9f26f62bad8ca7d14d74418a85782b8a45c905fec493384458
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocd@sha256:f22e296a5c8c3fa004eaa4c706c05c283b1e2de62a2a3517be53c78fa6fbf267
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocd@sha256:76893056eabf7a1b59fc09050d9397f9aba7e5d0a05f012e36f90bda6d6a17bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocd@sha256:9cd9a3b15aae1fcf1b8eb49c25556d99ef99b642c8a000ae3c991fbe070af2a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocd@sha256:2f3924f28c0019605949a3d2d8e44c9ea9f1a259eb5a6209f566755abafb6e01