Sign inSign up
Cert Exporter

dhi.io/cert-exporter

cert-exporter 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

2-alpine-fips-dev, 2-alpine3.24-fips-dev, 2.19-alpine-fips-dev, 2.19-alpine3.24-fips-dev, 2.19.0-alpine-fips-dev, 2.19.0-alpine3.24-fips-dev

Index digest:

sha256:350e0344837dc41187346b4f3cde780a136065e188f3e4420ea22f986e50d452

Manifest digest:

sha256:b00092432b83be0012d66c162b9100807dec57b74a99e0e40bdffa5d8d228cc4

Size

27.42 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cert-exporter:2-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cert-exporter:2-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cert-exporter@sha256:b1ab58cccad1fe38e3c0bfcdbb7ac411e37a822e9e541c13285dae72a31ac07c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cert-exporter@sha256:fd3be4e6360c5335e0d98e91c708f7ac19ac4385fcbf8645ca4d5b9607637752
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/cert-exporter@sha256:2d282d99b8242a012148dc93f51544de76934d79ebdf6555d0c1d6d311d7f19a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cert-exporter@sha256:97512434e4aa180bb5dd81ad55c0219ace3eb9e56561ac8e0dcdca2deb55c934
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/cert-exporter@sha256:8350b0e03b7dea1b43735dcae0978aaa3aefd3516b17c82ddc18ef736084abe7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cert-exporter@sha256:9c3579ecf403fccbe410490225b395c8f6018a7c90b4b67216ad21b1bcc3dc5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cert-exporter@sha256:c58c1616cbb42ab1bea5c9e5bd8f2da49a78893cd4d99979d18f044af478287c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cert-exporter@sha256:3d20ddc824dc89a512167ffcb59dc4a570dc4251a59700bdd98eb87c8642f6db
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cert-exporter@sha256:7078d00b236681026b6eb128859cf79e7f64e0e4dc8e3fbbf5b6f6aee3ebc6f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cert-exporter@sha256:7c85e6838df7cbc6436f137987a11a216aaddc0f7bfdb00afb979af151c690c0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cert-exporter@sha256:138ec417bfa9f92db11a6504e7fa69192021cf2805f941bf9350dd7b3e7c0168
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cert-exporter@sha256:6b2a55c03bbb1c881599e05fc8575e0dc578fb5c89c20323fc9ba886acb161bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cert-exporter@sha256:32cd3d7e535f30f36f3eb901e4348057930bfdd233665e7aecd188225e2b0974
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cert-exporter@sha256:3fa351cf75122cce704900b8d379bab0e7942760c83fa0753893c826064cc570
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cert-exporter@sha256:65a98113faa61c04e55f10e9eebb54416996ca72cc952873b33612a162775669
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cert-exporter@sha256:ff23a665f2db00bec6f6624c5d4348260a1b4c2bb1815bf9873d3e236dfd7645
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cert-exporter@sha256:3e393d9c34b68d8dce2bc2218f66bb1390682fafb6bc6374686993f71f7a1070