Sign inSign up
CouchDB

dhi.io/couchdb

CouchDB 3.4.x (dev)

CIS
linux/amd64
debian 13
Tags:

3.4-debian-dev, 3.4-debian13-dev, 3.4-dev, 3.4.3-debian-dev, 3.4.3-debian13-dev, 3.4.3-dev

Index digest:

sha256:3f3c5220398dd4521878914e333f5d09273f49a974a23d5ad4d866e23f88a5f5

Manifest digest:

sha256:29501273bb69380391412a1990cd8e3324d8f1a8b19917c00571a96757398c65

Size

101.01 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/couchdb:3.4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/couchdb:3.4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/couchdb@sha256:b4253223d6dd0988adda2e82f0f0703fdc920df6312d4537daa85de6707d7433
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/couchdb@sha256:14d66da5317d4638e6e690e3e9c044bbe1470e70dfb573f2355e66865949488c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/couchdb@sha256:52a0d5ae552f3f6e920b03dc02b414ca15469d378a9a02a96dfd625f45647902
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/couchdb@sha256:b417c406d28044a00d56397806ddc67ca469bbfe6dbafcc3009509d5220afb07
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/couchdb@sha256:6cd8054326df694c4301fa46c5fe2426515052390d6c6ac51afafb59cfb672c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/couchdb@sha256:eff0b2498081c1025caafbf18e76e6528f5cd183cf07146934e431be94ba2b8b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/couchdb@sha256:4e4656a491d9047f3923815bfa491acbad3aeb5b1dace9b93cf7946f979e73f9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/couchdb@sha256:f20bb98391baadf41120e8dc396d224b9fd0e579991b48dc70d9b1869224a56b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/couchdb@sha256:02aec7717d4659d9d41b4e12f06323c88cc0535a840560d1a8e9ac98588cdd18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/couchdb@sha256:c57fa40c30b88bb51c62aa15994ef64afebc2c727fec4e64f0b4682b5638ed8a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/couchdb@sha256:4da8d1be6e36f740deaaebdb3066be6dac2dfd4dd2ef1c7dac69ce5e81eb9101
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/couchdb@sha256:fc9d31a36f9dc3a436dbf41a8e0bf9b5ef0549fc323b528861cfcf459f63b2d0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/couchdb@sha256:6d9750dff33a75a805746d5bce154104c7dc2c401f8292181d2e02dd3887aa51
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/couchdb@sha256:9558d1b530dd61c0a330c543b6fb2f4f69cbd4b577037a5669543a63ae20bef4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/couchdb@sha256:492395b673256121740c18d511ad4c9c3283af31890f2a79281ba84a29640f10