Sign inSign up
DataHub GMS

dhi.io/datahub-gms

DataHub GMS 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.7-debian-fips-dev, 1.7-debian13-fips-dev, 1.7-fips-dev, 1.7.0-debian-fips-dev, 1.7.0-debian13-fips-dev, 1.7.0-fips-dev, 1.7.0.1-debian-fips-dev, 1.7.0.1-debian13-fips-dev, 1.7.0.1-fips-dev

Index digest:

sha256:e330b2a4c204847fcde0a4bd51e4f8a3d6acbd2518d43b93431501dd4cf6657e

Manifest digest:

sha256:e9a13db7d31cc8374813667fa6632afae38e41e4bcb9f1659415633f49cfefc4

Size

714.39 MB

Last pushed

3 hours ago

Vulnerabilities

1
3
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/datahub-gms:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/datahub-gms:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/datahub-gms@sha256:04d1cbd5d09033469d2543464755edf358b2e20fa3f9b20fda1c9ef38d67b006
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/datahub-gms@sha256:eede6eafa6b9bf831ea1086527012ed9a3ae44d66fca006e7b607f0003239a17
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/datahub-gms@sha256:4d498a5ee5f19f71f5887fb30d053846035f55277cf14d65ab8261ac27e2953e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/datahub-gms@sha256:7d7d49f5e4bd164e2c4b7abc502674ec837334d0a196289657f151672d7fc1d5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/datahub-gms@sha256:e7d6b6f1f42ed01dc62133a918765c87ba4537ebf5f3c7be8951128f8bc579f8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/datahub-gms@sha256:c213c0a41000496612ea0264120dfd8dc97681f96b2178fd56c637cbb9aece9c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/datahub-gms@sha256:ef9504f4461f8addfd3b76162bccc48e2d5dd93f221c0617801f7b23e8baa2e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/datahub-gms@sha256:359cf27b76fa812e23260123e5a3a892950471ec0706c671fa06e6388828fe65
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/datahub-gms@sha256:08f7f9775805153c3d69cdd9aeabd5b89ab7a0af5ab297e53941bda6b86f5f72
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/datahub-gms@sha256:615b630b51cb5806931074ffa679adf589705fb96ac7e43af2c163baeb26c7b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/datahub-gms@sha256:1e87526abec2166e455826c8e982727f940ec64482132db84d93749d7d9af2ed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/datahub-gms@sha256:f3abad8b57b34a58e047f5adf0d1987f66d98da7d6b9d236018a971cb34fa881
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/datahub-gms@sha256:fab3af1ec8656aab57db4985e6f22ce8bb65e1137dc36447553833bc7d197f02
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/datahub-gms@sha256:7cf61b663130bae51886e084b8c3b2819ab523afcde4e194db309f32bef269b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/datahub-gms@sha256:104ad9200b53e69c38fc327bb8f7ff5aa1456d0517c6002d5e17155ee50e04e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/datahub-gms@sha256:cdb4fdb7216f7f9f698354d0eecbeed9c81e74ebbf27cfc0d17c1b55dcd4d930
SPDX SBOMhttps://spdx.dev/Documentdhi.io/datahub-gms@sha256:c2054dfc4f15b704bb0409ec4158f4c4a95c2a9a6ddf8e412a91f4d6720f44ac