Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev

Index digest:

sha256:c9fb12b827d39ba03b54ae62d7c239c6f91db9ccea77dbda549d1c38404a87da

Manifest digest:

sha256:229f93fde424b85b40c7c4dcfec9f392a76905e0f59e2cad5dffbb2b7e0a7bd3

Size

37.81 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:83e88fab1fecab22be19f86e2546dfaa9ce53187532a88aa1a382ab3dc5690dd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:46281516b350359ca4d9f6ddd078eddf5e35f7031deef03da1c69ce677ab4273
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:17579ea378ca3bc01d92c8ec561dc882e4ecb50c7f8547c5ad82e5aedac629e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:93cc69716da5628fe0164d49234b1e426ae07a0d664a7c89f2e6aaca59581365
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:c444d687da9027c8b1aa98597e3f954fa39353f28a3fda1672f52b5e0a7cb257
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:a5c9f2b8800563084df0c31eb0275ec96d9945ed01b0021c33ad0c526f0447a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:39986d44e2befd5d095b25db3e01fd935bd1cc411a2b2de7cb4b2ac9c00b7604
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:d1c9a7c043b38b7e15eaa712479c4a341ef420c70716b055fe77b3d5f34e9b10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:b8390496abcabb965cd6b94981ec0d3f53ada1bd98b38eb1a364ae837ffcd288
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:509cad47418edbdf5fc0a4800510f7608ccbfee1c26d943c6e6d7aa57bbeff82
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:d469b70d4c4fc5b6024c0dd2b2202b8c6b0bcd54b298ff24bddabb92b25139ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:3b135fdf057be9179f7fac0d6529750f0f8269f6ad5dba70f67d49535832fef3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:fe09f759f058da846b0e9278bc82c211180a75da1d309732c3442477f9ad8743
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:452a1874343eaaa4034ddebe9c36705cda2a68f3b878426b034c9aa20b2ada1f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:e70f87f7cfa02db267153be249943094930f660be2369694a87011ddd87daaa4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:3671e171505bc66286deea36b73ac14c09204652c9836d421abd7c3f958ddf30
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:d629663b2126bbbe82cabbc1e7e5a6cb8145d171ad78e4c7c19a9bcacef349f4