dhi.io/dapr-daprd
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.4-debian-fips-dev, 1.18.4-debian13-fips-dev, 1.18.4-fips-dev
sha256:51304b8c998aff49a78db65fcf8f21d72df8636d12598f37bf60c6fbd39ac5f4
Manifest digest:sha256:17a0bdede3a00993b708e133ae2d04d4e98baff6b4c1679189dada9e681564be
Size
129.94 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dapr-daprd:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dapr-daprd:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dapr-daprd@sha256:8a397adb68d23759d730ccecc6c2f9e7f3048a0f24c47c71b492af5bf5e8d160 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dapr-daprd@sha256:e8d2bf036e5cfb7e7b87860611ce8a4cf611a4d25640e097419a62be116d30ac |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dapr-daprd@sha256:5c62372abf49d4e45d5229011a58fcfc0d5193e52f39b13a057871624cbcb06a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dapr-daprd@sha256:9b532bdd3d5230db62a6ff239d248878d29afd2df8a87cdeb764b550125ea53c |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dapr-daprd@sha256:fa8d43fe9b191cff3659f363f67f5e4152cf7787a38bec2a348535180c196bc5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dapr-daprd@sha256:97de142671a000737ed0c1661dd926bef739da1fe28a1bb3b52939ae19eecdf6 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dapr-daprd@sha256:371884312f2528892768f6a0263bd93db22e9087a729792d88daa24a7a23b789 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dapr-daprd@sha256:cd41ad06f4b281f877c5a0b35f592c3d8e0c30ccdf50f0db5a5a7257684446ea |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dapr-daprd@sha256:8b6045415c95befe8e8b64ceb9ae1d898d9f5c18dfb4f17901513379f7ea2b6c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dapr-daprd@sha256:b7af0644bf796649bbefa2e7d058d54ab7c096a6fca1a23ffe945266d7c91201 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dapr-daprd@sha256:2c4dede253c15a4b707a05353c9be6d7429ab3f0b9bc101948bd5344ecb10e12 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dapr-daprd@sha256:06f426ac48d2b6832d41fe4d14925cba22ba8fb147941ccf04624148d26b57f8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dapr-daprd@sha256:86da19494ed80f3b6d641f12315cf2c3e350b93584a7123a319119d35d946531 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dapr-daprd@sha256:627298663fa62a6121815a4f3ca524319f6ff4b1c938ce58eb33ff4e8cbd3723 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dapr-daprd@sha256:c1b1af5030cffde9352b72888d92d4bb0f207fe3bd1c9859f07c76d48c4ee840 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dapr-daprd@sha256:2b21abbd2d52a43a82a0a39460d5a61d3f6796a1172db155fca6ffe26686c851 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dapr-daprd@sha256:a56115b3b7a493eb1909b1226079074b242f60ed284d599f8ae7abcca54c84eb |