Sign inSign up
Hatchet Lite

dhi.io/hatchet-lite

Hatchet Lite 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.109-debian-fips-dev, 0.109-debian13-fips-dev, 0.109-fips-dev, 0.109.0-debian-fips-dev, 0.109.0-debian13-fips-dev, 0.109.0-fips-dev

Index digest:

sha256:c964e665ee69f246b2d49d902924b49876fb51d5aaca4376eda3f0f3c64d5c0b

Manifest digest:

sha256:c86e6ba1a3b8edb323e7e896875be27d986904fc4ac4f675094b20974e36adcb

Size

68.61 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/hatchet-lite:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/hatchet-lite:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/hatchet-lite@sha256:8a91c126112237d1947a816fed7ca2ce7bb51cbc532025b903b1bcd015dcb8bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/hatchet-lite@sha256:780c85b016f85813166f2a83ee2457d4895ac8d5bcccb91f953808d5a4ebb050
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/hatchet-lite@sha256:f90e3e601808b01e374eaf1e2a6e517c2335c06dc437393e6277b52bc7767fea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/hatchet-lite@sha256:14e2e5d4bc0444df8f79bfa9d2dc74939de8927ed749f8e2acb034c02100fadc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/hatchet-lite@sha256:de5866432c2b046c184e280504316cfe3db5de22a35fd5957d6ef4594e10429f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/hatchet-lite@sha256:84defad68f1dc95c92976e8e989aebc9d33393bec4cd9ff31d2c47a002e4bb74
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/hatchet-lite@sha256:c2bf0ab72764d4132bbed7129ce7e85134043db26d0240dac4e9b8472961116f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/hatchet-lite@sha256:641d650d7d39cde7bb9c95f67acb324d78e48a0ab63d3dcc3d120bfb6e2db5ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/hatchet-lite@sha256:c750a0197b487521ff8a0e20eb833b8b0e05b700eb03a4cf6dff673abb3c26c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/hatchet-lite@sha256:d3480d401d9b1bf6e5a1ef0245ff11a75318c4701ddd5b1104f4de3066b7a7f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/hatchet-lite@sha256:e4c1882a658e48be6c130921e50d20eb4030253ab8962c70514a8583a3bda9d4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/hatchet-lite@sha256:2bbb3db657512257db817892b1701e4f3f39d367342875306470e8cade16e41d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/hatchet-lite@sha256:3a149ded297c6650b9a26674ccf9bc57652db47f55eaf2428f645a1a6dbd2bdb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/hatchet-lite@sha256:f4b7acf4c41dc6bf3e123c6226f2a82409152d37ea7065641d0fb48128ea435a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/hatchet-lite@sha256:41570b9f0842bdf6b2f7168f005d4deb5d9cec08a7d7a68a8b1db13d8fae2d07
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/hatchet-lite@sha256:76d7b6f2ab04e09222aad169a546d34f41b68739e14ee6cfacdbbda0c2bc1d1e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/hatchet-lite@sha256:6ae9a6f23c043eeda69f6b96a81ae883c7151a74fd97064794d842a673d12db9