dhi.io/fluxcd-image-automation-controller
1-debian-dev, 1-debian13-dev, 1-dev, 1.2-debian-dev, 1.2-debian13-dev, 1.2-dev, 1.2.5-debian-dev, 1.2.5-debian13-dev, 1.2.5-dev
sha256:3394b67ef0380df04638e48b35787dd651c327b3c3bd19473b702affbb3fa8d1
Manifest digest:sha256:7f07b68af8be3603cfd21afb15b67e57453b36edb6beea4c89f4c0ac7cc7f0d2
Size
57.77 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-image-automation-controller:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-image-automation-controller:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-image-automation-controller@sha256:f83b11b05e21091e7686c977b9af41fab08c9fe5dac787c24808aa0c9c9a6fb1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:9d27aa3d86a997d9477d8d40b163952a75127032a5963df6c04b707643853f77 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:f4e7f94348833f7d285ec048775c533fc4d05e4ed35f53aab5b0a7c8e79b270f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:2a61e00c85a7d9ca6e7edf3a5ee4972c11aad2966916c0ccb18868d740b9404f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-image-automation-controller@sha256:4ea541e2d5f588d7d9c6c056fb5a501dd3792c6abb68eabac27bf1164caf5f0f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:b3d2af51acc0988f6da2a96fede7702aac9ec0fadf10eed9561f7d7310a6b673 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:c04186637c8b8e6f3fb7b5082f0925cd3caade92fd069fed9f5c2c90e862127f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:8a3c42cf7a7dc9202e1551fe4f0530dac65ffd7de4bec72deb48c429962991fa |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:871d9d1f12f369e4cdf7911ae3fba069cfb155d309a216a24c42b96d748787f6 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:2efaa806bf0f823222083478b0c47358bd2e887e3d07c7665b13bb134c641837 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-image-automation-controller@sha256:82e13c413bcccddc4e979936c9ef82cf4235ce557512c3f19e043bb9e8b0ba79 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-image-automation-controller@sha256:922bc7771f788a0da9e47ab334e6f48f88a75cb27d6ef12c0b428bfc3292f38e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-image-automation-controller@sha256:cd83c0cd3e246e4bef47b702b9b3807cae3c2f03f7fa43745ad12eb39b202294 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-image-automation-controller@sha256:bc76ff313bc244f5a50b1756b4af51842d93aed6ca86d6b6343214043a343e62 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-image-automation-controller@sha256:610b7423c66043a90b6bd34ecf6adb34d8a7b7dbe6a0bd25423a3ae125b74212 |