dhi.io/argocd
3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.3-debian-fips, 3.5.3-debian13-fips, 3.5.3-fips
sha256:eaeccacc054f262da9d8b6e726e3b7e8628b4d793c01d3c57b432ac4d75a8e49
Manifest digest:sha256:b7e1c783916b4ad70cbb57ffaddc38aec91a20dbc07a0323be94427b10e7b212
Size
117.09 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocd:3-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocd:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocd@sha256:3c95f773a0ffab3c42b97df9b128d740611cc16e78a92445d67c1821128bcba3 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocd@sha256:a2d746fb96073f38cdef8b1833499cba8ea04a4a1359e995d4d50e6f495e02ad |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/argocd@sha256:2e133b3c4fa61dbe836807746fcc7582471d5e613a5ac6460c67bdf74c73ed87 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocd@sha256:86fd8cfdfb174249fba622cb461f7c68e2f6e794b80a0d0e77a09e4f0718a243 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/argocd@sha256:f5c5f069c5c4e89f8c5918010920935117a5566546f932479195e64ac5e762d5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocd@sha256:f435890fb724a0952e02d8684dccbf384d328aeb1724aa6e0ddf62e55368ddc0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocd@sha256:d18b1499b966cf36deb8153d151d0145893ec2befa07c3c79d4d28b6a9b4ef56 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocd@sha256:7fd5fd19181b4b8ecd5f902847203827bd192425f5d7137adca214291c1afc00 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocd@sha256:4571d130dd99fc72acf547af58aa7d103202ae72359e18c9cc3d6dd6f0e8db40 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocd@sha256:44037710f5af2293609758d31accec66da7266c3f5c6912e299db670d0802052 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocd@sha256:65044ed2db37420bbb0f416c519ac911fbf563280efb51dd345fea84c932cb21 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocd@sha256:9b9148ffcf36cb0a2a8b92457b31d1b3615518dad75146d9a58a447892baf1b2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocd@sha256:6605e096a06b331c29b75fc2614f3e58fa8a28f9b35a5d927d136c6b6dacff3d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocd@sha256:57281984e76d9de4a48a32e8ba35a9d4d1702eae2987a91ac4e6f09a0ffa22b9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocd@sha256:8f1c03ae6ca5fa3860c712d9d28087aedc0c971322b6e7d00a2ff197113a4155 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocd@sha256:5cfd271094dd88d1bea3aff331fc3e284e6d802d5f753988e186b16cf0f36162 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocd@sha256:90fbfa52567d6f8c62ecb3d9b87dc305acef6f6d19728f4429601ca6d44785a6 |