Sign inSign up
Helm

dhi.io/helm

Helm 4.x (dev)

CIS
linux/amd64
debian 13
Tags:

4-debian-dev, 4-debian13-dev, 4-dev, 4.3-debian-dev, 4.3-debian13-dev, 4.3-dev, 4.3.0-debian-dev, 4.3.0-debian13-dev, 4.3.0-dev

Index digest:

sha256:d10e9ed414a0438ac7c7b499103af824cbfc425cf6b705cb339fba54b97bb7e5

Manifest digest:

sha256:54c1e6ca91d20770a6218badf3598a942c27a003712b9ad0592af9e067d6b0b7

Size

62.46 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:f345fc1c94b42ea63d438cd23aee718a17e370abefd71277dcfe0e7a0097e28d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:f194febc4540b6b4e8c79516e913b7642371872e49bb8f809e245fa98bb5cd7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:eef5917b11bc7b8f3fbdf5bb747733374e3f9740fc9674f2e1c61727e370498e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:e8d35410a024399619efaf813eeaf5910165c3cecaab4ba426b187b05094c139
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:abbddba120d3b6f353131aa14b6d91f4a4664cb61c53f03ecdc1ae3c25281963
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:bdee0a09ee8b0428b0579e2de01c05c90895531f73ddf82a3ef18567440c8305
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:67b88f34c2e0e575dbde3387f2d4cee392e5226806bb37935bbb8880d6db0cae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:00f8249a251505d18208b38919f610772e37a3809c663ecd876fd858a9dd8bbc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:38cd1c157a4916ff9df5e468cb20be9c891324098f263bb5ed4707baad7ff62f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:fae415a171f45df70c78f2d0d28a4ce0652f45c801076d8f9b4a79f669b453bf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:add72d7927c928f59372ecbb2f311e4dce2d8c08c851834a5808c921c63ee569
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:7ed38e963903af80ac7607f7dd89cdf84d74bf383fc4f798425d7dbb971fa662
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:5c2b886912210cd7d32a8968a470e0a68a2352a6f18378c933f5158a7168199c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:fce8033cc594095a5f928cc583f3460cbf1c65f01271445817ad4c956a65ce92
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:3b0ce02814289952219a6d3615a884aca2ed30f2318b979ff3a0e472108167fc