dhi.io/argocli
4-debian-dev, 4-debian13-dev, 4-dev, 4.1-debian-dev, 4.1-debian13-dev, 4.1-dev, 4.1.4-debian-dev, 4.1.4-debian13-dev, 4.1.4-dev
sha256:18e5f5e39d3bef2db0937ad788dd297c252a1aef3ce04bd9dbd29acbebae839a
Manifest digest:sha256:11e8cbc4e481bf98a96943005a6ff6e075179aa98c27b5a8118ff7ff65afbf15
Size
89.26 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/argocli:4-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/argocli:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/argocli@sha256:b629956f576834249bf87d5e7db023a8e5d00ff291f35e5e0237c35f73f00a18 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/argocli@sha256:2ba60b89a20b0bea4aa1158c813ec6749ef84f94c6c55fe5b5f0d7ba1fbc29e4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/argocli@sha256:4475816228dbdc44dcadfe5efa3f04c650dbde735a9c0c3ad2c1711e691e7177 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/argocli@sha256:a858761a2f622bbbee42e6bfd177eadd35817fa822334b7c6e8ab47fcd1b4992 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/argocli@sha256:33e2f8fca86d3bc0e770444332a598cd456f1a7824757aeb8fc262c79e77c077 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/argocli@sha256:039372e8174bc319662fd9a00e253514bd1e87e401255d68084649a5baf3cea0 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/argocli@sha256:8c267b3df578a9872a91b13a58af72ed37c31fef8703b9fb155c3c1fa87be3f4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/argocli@sha256:ee0e601843d95209a4d681720ca4075509a1f1f4986715706e99807f2e3b6a8e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/argocli@sha256:e37b6c2f712b3032e45af223a966602382b21f520f91910e5926a658a6d72d40 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/argocli@sha256:18490d7decd19ef7659601cea02de03ba12348fc65a9ae9dd06801cee11f62ea |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/argocli@sha256:fb94b998887c292fef6932df40c6ee5d5c402431122237fa744516718416a193 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/argocli@sha256:5b80eb38b02a0680fc9bcd82b8360293805e137321e2a84a64d057764821b6bc |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/argocli@sha256:f45262edb852c5a4fa262922a763fbedfab00d07ed13c9fb492cad0e6b57efd7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/argocli@sha256:c9711a688ba197f39a1bf6a15ef54d8d6f0c0b520b494203ab6cb6c92d6188de |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/argocli@sha256:c641ef0bec5667663f1af8de47047490f2a0e16f75d2df4582ea04ad57fb0ba2 |