Sign inSign up
Helm

dhi.io/helm

Helm 3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips-dev, 3-debian13-fips-dev, 3-fips-dev, 3.22-debian-fips-dev, 3.22-debian13-fips-dev, 3.22-fips-dev, 3.22.0-debian-fips-dev, 3.22.0-debian13-fips-dev, 3.22.0-fips-dev

Index digest:

sha256:8c16ad053bfd6005405a836409c70d67c4cee5ee264f47a23c970721b4dd21a3

Manifest digest:

sha256:fd759d64ab0b8deb17bcfbe167f7a4d3b6879e32b41397d0795fc60a557ce38f

Size

60.16 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:3-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:3-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:c25cc7ecc17c256a1c76de857fa2c3bc9483a567c9ff05c76a707452e1e1eef2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:7fd3945ac8513c29535daa02a77e3e5e6ae36d1ab69442b5901fff4195511af0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:9c537f4a49dd79b09622473cefc545d34b8af36989dd6460cb4204b2f68b18a2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:4aaece0fe00cb4061cf4d21e46ff7e707bbda6d52b46823a4dd6051c1dbea05d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:dd719123f0960cfc8dfef3429711ad0b72bcb08b3cc6db5d3d83ac2be9911f1a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:da2b75bf997c1d3c688417ba6026181cecfc43da157fe09ee63058be1d8412fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:c059baab004f117d0bb30c36b9269c0171de0dc7f2f85545763a4fe66a895977
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:02358b05d2f16b86c5a44b3422781bee51e39157c3a38649b7223ea7728e899c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:c7904e2c3dbce50f768774301fc3e37dd21ce337e0dd71c7243f632f69a4859e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:5428a3053d3b0bcfd95c2bccc8227c82c5b669b2e2123ba3e47f3680363eff65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:cb987be9c14caa9f9617570845510cd57a8b7864c8c9f6a4511e44c38f2efe07
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:069c6651648c6e6aa8b683efe653884c7fe722cd45493f775b9b609a6be66523
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:706f85084096a59c1c615a205d1f985de256959cbc3ea1d3366bcc9d948263b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:18d026ad80615e1424755665a05e02f162783a4d4beb57bc6a5459cb690d3335
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:e240b6038df78baee894e2295cfe1630d572128b25630dfe630cc9a6b5918220
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:cd3fc8d9257333eed562b85c605d8427ae1b9dfedfd72d071c69efe4db4412ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:e182bc7f746b391adb228b617942c5273079f3b5317fce4a07aeac52a70ea6a1