Sign inSign up
Certbot

dhi.io/certbot

Certbot 5.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

5-debian-fips-dev, 5-debian13-fips-dev, 5-fips-dev, 5.8-debian-fips-dev, 5.8-debian13-fips-dev, 5.8-fips-dev, 5.8.0-debian-fips-dev, 5.8.0-debian13-fips-dev, 5.8.0-fips-dev

Index digest:

sha256:45fb1906fc49da68d1461ba2ac22f5f91245eab1348bdfeee03d1a058ea55791

Manifest digest:

sha256:7596faf3a72a3bbf199c01d40d98485c96fd711771d1514c6acd7146497951c0

Size

37.81 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/certbot:5-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/certbot:5-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/certbot@sha256:6ae2373efa0cfcb2611e1202f0f0fd71d597f35fd1ff566acf89cd188d404aab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/certbot@sha256:cc69ed9dbeecf35f95384e906a3ef2043e83fdd8e003353d6824a5786193a89b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/certbot@sha256:d7df23bce1ac7a1c46b00f181ab5e1eb6805d22c4b0d864bb4066bd5e39ecd5f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/certbot@sha256:35bb7905a21b05f47da27d35bc81db42bcf648a8538e3a8abcad7981d759495d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/certbot@sha256:9a83826565dd41fc8c94ba428031db5864e902c5d9af42ee44a1eb2e10989898
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/certbot@sha256:cb84baabfbd3969ce0afdfe05e87fe46bbe57217771e93cc810bf69f28e0bd32
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/certbot@sha256:50e86b68a1caaec9f40199845f376afd8df6d74d9afed2ca847a2333899c97c6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/certbot@sha256:5643d6267535fce49477e899396fec3b106b7e287daf2246831f4cde694887a6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/certbot@sha256:6efcc37b72c6786666a8b97e127c62c9aca5396af3e93c317047d4e730ac422c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/certbot@sha256:77d607dd7fa7fd6df545be73ed262babcaefdc15fab6be9a6ff170a4ea7558c2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/certbot@sha256:575cfdbfecd9b08ed3913d46859d78fb3f6ed73c281afe87c85b28865a3488a5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/certbot@sha256:19fe8cbd9420ff9e61bd0e10aeb88821ae45f79abf5a2c05e6654f636b847bf7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/certbot@sha256:b5b26571e6b4037f172a971055d971b63836f81df1f61457bc0a99d6725630a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/certbot@sha256:1e4404041e6538777444b046cc6db05e57765595e4e15b250011fd1b5ab2dd7c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/certbot@sha256:9d0fa1e54e125d4b4d0010f251135ac025d573359db452bf8a2885301fca3784
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/certbot@sha256:f43f93355512685098efa555b3e58de6fa3f89a6270016ba44ed65cfdb6a4878
SPDX SBOMhttps://spdx.dev/Documentdhi.io/certbot@sha256:f9f2ad7775af6e4c70de52b480f1c5a08b98ea9cacac5942c403eab09629b03e