Sign inSign up
Distribution Registry

dhi.io/distribution-registry

Distribution Registry 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.1, 3.1-debian, 3.1-debian13, 3.1.1, 3.1.1-debian, 3.1.1-debian13

Index digest:

sha256:0ab1da4e315772c290f8b61d67380c812a04ec1223eff18cdca85dc4fb09ab7c

Manifest digest:

sha256:5c35226bce31315db52168a1bb070aa77588711183781ab83fdac66b85208487

Size

14.82 MB

Last pushed

4 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/distribution-registry:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/distribution-registry:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/distribution-registry@sha256:3e54e4f0d7fdc269da49a9b05c8dbdbbe4fdaa0a4079219feaefe5641f1265cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/distribution-registry@sha256:e459f727521fad5260d03a3e5f0da02a48dd21dc30fcf839d56ec9141fcd0934
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/distribution-registry@sha256:8995d224fd3590599d0cea1c82a1d36c586c37a894e11f86a92c49c6e3bc530a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/distribution-registry@sha256:3fb1d31c83e20e58a47ce17ca44c59c23b38655c3dacdd6e59c1f415344b0255
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/distribution-registry@sha256:826f2715dd6f4ea6ba4c84877c909003646a2b7b5585c1568db9fb2324322d4c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/distribution-registry@sha256:36835f592493b09af1a989844076e64c7323bd5ee68b9dd1e01c95caee2e1294
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/distribution-registry@sha256:68ea48f376d6bb6048210b61d69df5f7baaa5c3dc8528dc2df787b6230f2de5c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/distribution-registry@sha256:e15e7e8ab6a71c46335045b9337295c4ec0618ec5b238ae16f0eebd09c0a111c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/distribution-registry@sha256:3c70faed8a8000ce00527729b273d131b0e484912b9e27abc4a588ce018629b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/distribution-registry@sha256:b6cc5328dba7ac08a24c8f161a5d3300be46b2f1989c9052772abd905443bad5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/distribution-registry@sha256:b442d594cea2ebecbf4fb84e4609063c1dad5e3390b6895c666a6a5ffea1db73
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/distribution-registry@sha256:6a1e39f71272a3d9654032cb9e8447de5155b95cb4b3cceb79bea4d7d8e52b06
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/distribution-registry@sha256:f344ce14bcb265082ca2cef6de1c5af1e1975704a203bdcfac4069baa8636e9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/distribution-registry@sha256:252b7b164ff02aa3d1c0ac71137ba27a172fa0ee18e37c7dc06595b869c6699a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/distribution-registry@sha256:ad789d6278196772bc3d413d65981affab909f20ed2fab7e05a6d17a3910cd65