Sign inSign up
Argo CLI

dhi.io/argocli

Argo CLI 4.1.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.1-debian-dev, 4.1-debian13-dev, 4.1-dev, 4.1.4-debian-dev, 4.1.4-debian13-dev, 4.1.4-dev

Index digest:

sha256:18e5f5e39d3bef2db0937ad788dd297c252a1aef3ce04bd9dbd29acbebae839a

Manifest digest:

sha256:11e8cbc4e481bf98a96943005a6ff6e075179aa98c27b5a8118ff7ff65afbf15

Size

89.26 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/argocli:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/argocli:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/argocli@sha256:b629956f576834249bf87d5e7db023a8e5d00ff291f35e5e0237c35f73f00a18
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/argocli@sha256:2ba60b89a20b0bea4aa1158c813ec6749ef84f94c6c55fe5b5f0d7ba1fbc29e4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/argocli@sha256:4475816228dbdc44dcadfe5efa3f04c650dbde735a9c0c3ad2c1711e691e7177
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/argocli@sha256:a858761a2f622bbbee42e6bfd177eadd35817fa822334b7c6e8ab47fcd1b4992
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/argocli@sha256:33e2f8fca86d3bc0e770444332a598cd456f1a7824757aeb8fc262c79e77c077
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/argocli@sha256:039372e8174bc319662fd9a00e253514bd1e87e401255d68084649a5baf3cea0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/argocli@sha256:8c267b3df578a9872a91b13a58af72ed37c31fef8703b9fb155c3c1fa87be3f4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/argocli@sha256:ee0e601843d95209a4d681720ca4075509a1f1f4986715706e99807f2e3b6a8e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/argocli@sha256:e37b6c2f712b3032e45af223a966602382b21f520f91910e5926a658a6d72d40
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/argocli@sha256:18490d7decd19ef7659601cea02de03ba12348fc65a9ae9dd06801cee11f62ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/argocli@sha256:fb94b998887c292fef6932df40c6ee5d5c402431122237fa744516718416a193
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/argocli@sha256:5b80eb38b02a0680fc9bcd82b8360293805e137321e2a84a64d057764821b6bc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/argocli@sha256:f45262edb852c5a4fa262922a763fbedfab00d07ed13c9fb492cad0e6b57efd7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/argocli@sha256:c9711a688ba197f39a1bf6a15ef54d8d6f0c0b520b494203ab6cb6c92d6188de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/argocli@sha256:c641ef0bec5667663f1af8de47047490f2a0e16f75d2df4582ea04ad57fb0ba2