Sign inSign up
DataHub Actions

dhi.io/datahub-actions

DataHub Actions 1.7.x (locked, dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-locked-dev, 1-debian13-locked-dev, 1-locked-dev, 1.7-debian-locked-dev, 1.7-debian13-locked-dev, 1.7-locked-dev, 1.7.0-debian-locked-dev, 1.7.0-debian13-locked-dev, 1.7.0-locked-dev, 1.7.0.1-debian-locked-dev, 1.7.0.1-debian13-locked-dev, 1.7.0.1-locked-dev

Index digest:

sha256:cc8b28afc040cbae696477fe00dde046a88a516cc5eaced2e6659c3f94999a6d

Manifest digest:

sha256:4cc6e6eaf24d5fe67f339b4b8f31f4f1e976b7df7d7df4b4d287b1cc4c72543a

Size

87.86 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
5
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-actions:1-debian-locked-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-actions:1-debian-locked-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-actions@sha256:d04496fa1fb68c48d54964e67bdefc9ec9d35b2097f3e19bf731aa80353f9cb9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-actions@sha256:0610b36867a84906540bcf8d66c6585d629379bf675feddf9f10a0da1e726608
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-actions@sha256:afd29ad728b2c91f4cede83c023878a1c013de05b06cf5018f07799f6984ad56
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-actions@sha256:7ad652c48f871481773767bc495e1380b9618e11b039beec6d444e1b88383716
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-actions@sha256:08f3fa287e55e09241690631b11b00879f54e10d979a58eea3ae95884844475b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-actions@sha256:9b38496c4efc9dad33f02aca5891894e612846f8e2d8fd5a8419463e84827b97
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-actions@sha256:9d204f8692e11949affa72eca108e9639f2d6a19673824dd132c5c8fe953f22e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-actions@sha256:537d9c1b41e9cb62390f9744d3ba9d12c9ee3545e2d53aa0ccdb002c4d954567
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-actions@sha256:142f8392129e9549d965e9f20a2c3a84c46cf0f77249cf05eb12a9fc0e2f0571
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-actions@sha256:7f44fc52396c691300b7a5eb5934e8232d22dd739c88031362cda8b4b6c859d3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-actions@sha256:dc53537190bbaaf352fc0c9e9df4241ca0c7a8de659a5986349a4e93b12d3180
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-actions@sha256:ef7d7d101b363ef3b32d353ca25d993e1db3811e2a7566a08fdc3daf91e18c74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-actions@sha256:405208825f4c18a9c533e15e3ca72ba2ca0345a400dc2018d7cf40ead4d57835
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-actions@sha256:830cbb170599967e706cad8ea3ccf93ee0002c795b21d5ffd73bfe885be9689e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-actions@sha256:5d4ea8874e9e120b352a77c3649537d85c3c256bbdfc9be1809ca192382bcd97