Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 3.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.7-debian-dev, 3.7-debian13-dev, 3.7-dev, 3.7.18-debian-dev, 3.7.18-debian13-dev, 3.7.18-dev

Index digest:

sha256:478559f822f24562c5772cc4cd798581ead678540021ac15a3d476b371e5327f

Manifest digest:

sha256:4e51f888aee22269c9d3e36ac6bb6ba1369da41a88c872d7ec50912752bf73f3

Size

86.81 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:8af5e5160313d576675ac0e5734f3ce0b751db66d4555be85aaf676174e1079a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:c01db7ac2d7cded7dab601f5f77844d653974c1afd462f3937704aaf6198c81d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:4d3cf4abc6b6ee787c131cecf9127cd68fe0d2047ebc2ff22e3788f99ea09f37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:50ff418a4a58c8945e4e06ab19dcc49fe4e5e5ac75391c14f33681a7592f8582
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:dfb717b121611ec529f09041edfc367eff03ef344054c3c5fd6807a726d98fbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:2169848df86c478a3c8af0a263a0f9a0c4c3d7880b6e16c47bb679fc0709b64c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:4029ecdb6163234eae118a024436d8640a1d09d2ddb3d2a3860b99413ad1c541
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:1e0fba47e19b1fb5b4e6aa1ff52d6ac190404361ffd064e551704b75f6bc573e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:7e6236955c069a836769f04586d1abc6b96897627766200d5688709ef4d804e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:ae788352b8d91b1d6e76627c5afe21e8cecbde9c739ef3c5008938479d5d5f97
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:ca68954e4d6eb8e560ead01e2d6ff0406800f7145237b844204567e6a7a93aea
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:a40d3afb37d8218e021be5390cfa3b1e5d0027d1113bace542f84727507f8b32
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:439e32d392f4e0077e724469eba76effee683da8368d6a9c92d5fd71ed8c1e0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:881e0c866363a3e0d6bb4a9f0296a75513251bd6a17f91103d04d45ffab0af37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:0eeb4c1a6476af88c619c388478f1ab77e634df1f51766a907ebb5e97df3357d