Sign inSign up
dapr-daprd

dhi.io/dapr-daprd

dapr daprd 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev

Index digest:

sha256:51304b8c998aff49a78db65fcf8f21d72df8636d12598f37bf60c6fbd39ac5f4

Manifest digest:

sha256:17a0bdede3a00993b708e133ae2d04d4e98baff6b4c1679189dada9e681564be

Size

129.94 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dapr-daprd@sha256:8a397adb68d23759d730ccecc6c2f9e7f3048a0f24c47c71b492af5bf5e8d160
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dapr-daprd@sha256:e8d2bf036e5cfb7e7b87860611ce8a4cf611a4d25640e097419a62be116d30ac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dapr-daprd@sha256:5c62372abf49d4e45d5229011a58fcfc0d5193e52f39b13a057871624cbcb06a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dapr-daprd@sha256:9b532bdd3d5230db62a6ff239d248878d29afd2df8a87cdeb764b550125ea53c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dapr-daprd@sha256:fa8d43fe9b191cff3659f363f67f5e4152cf7787a38bec2a348535180c196bc5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dapr-daprd@sha256:97de142671a000737ed0c1661dd926bef739da1fe28a1bb3b52939ae19eecdf6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dapr-daprd@sha256:371884312f2528892768f6a0263bd93db22e9087a729792d88daa24a7a23b789
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dapr-daprd@sha256:cd41ad06f4b281f877c5a0b35f592c3d8e0c30ccdf50f0db5a5a7257684446ea
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dapr-daprd@sha256:8b6045415c95befe8e8b64ceb9ae1d898d9f5c18dfb4f17901513379f7ea2b6c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dapr-daprd@sha256:b7af0644bf796649bbefa2e7d058d54ab7c096a6fca1a23ffe945266d7c91201
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dapr-daprd@sha256:2c4dede253c15a4b707a05353c9be6d7429ab3f0b9bc101948bd5344ecb10e12
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dapr-daprd@sha256:06f426ac48d2b6832d41fe4d14925cba22ba8fb147941ccf04624148d26b57f8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dapr-daprd@sha256:86da19494ed80f3b6d641f12315cf2c3e350b93584a7123a319119d35d946531
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dapr-daprd@sha256:627298663fa62a6121815a4f3ca524319f6ff4b1c938ce58eb33ff4e8cbd3723
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dapr-daprd@sha256:c1b1af5030cffde9352b72888d92d4bb0f207fe3bd1c9859f07c76d48c4ee840
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dapr-daprd@sha256:2b21abbd2d52a43a82a0a39460d5a61d3f6796a1172db155fca6ffe26686c851
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dapr-daprd@sha256:a56115b3b7a493eb1909b1226079074b242f60ed284d599f8ae7abcca54c84eb