Sign inSign up
Helm

dhi.io/helm

Helm 4.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

4-debian-fips-dev, 4-debian13-fips-dev, 4-fips-dev, 4.3-debian-fips-dev, 4.3-debian13-fips-dev, 4.3-fips-dev, 4.3.0-debian-fips-dev, 4.3.0-debian13-fips-dev, 4.3.0-fips-dev

Index digest:

sha256:af30d11d981f297c32ef08eef397b7221faa4fe095769524b4dd465ab50e2ea4

Manifest digest:

sha256:96ea5bbd84326afc62c91dcf1d02b0ee023dacd23837f0882098fb7af23f6075

Size

63.20 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/helm:4-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/helm:4-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/helm@sha256:e73c4f3610c364c83adb2cef47628d7b4f84d4ac381465cac6907cc63f49e71a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/helm@sha256:9eaa1653c6ecbf239f7ea839fcfea54ff481c76d10028d55bdffbc7d930a71ba
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/helm@sha256:877671d5ec3da1ce23da85b4aca51ced22df5eb9da12c0d7e97643930035fe6a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/helm@sha256:2077adcea45ffb0b7382a89c23b69c31d1de2b608b1d298b33598f0a2fcd8c76
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/helm@sha256:b82ec187e63bbe3de987f9ea66d8bf8af4bf1d3a5e454462d281e78077dd502c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/helm@sha256:4186c69283995b09568b8eb395bddfd5acb1549e09e40ae029ce83fc37bac07c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/helm@sha256:2b0ea2f6eacaf46157333580f8fd2832a565b74f96f38903b99af7cc12e47d02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/helm@sha256:a454872dd4b538b63cca1a2c693f172560b3d39713c99d924fda3976e0d37762
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/helm@sha256:5512667582157162a21b0686bfc74e1c100c364b21e3fd8cafa9356d898af73a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/helm@sha256:a83c75055d13e104ebd7b8184c7b164a19942ad330e273cf7518cf5fa26d1c14
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/helm@sha256:236f3af93d4242daefbc31ed89839e3106a322646e4bb592f3aeb8fc4db90dc2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/helm@sha256:e86dd2683d4468247251aa89cf0d8865f1cf499eee8b2234492d115da3c69750
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/helm@sha256:5afc6fc62ad70a2e63d2d69b1c6fb1f1b06215e34dbdd6927a1da4842114a809
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/helm@sha256:14c0a668c331a7700c52781fb4dd12da1ed33f1a93dd8c8ed04ece9ad141331f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/helm@sha256:e00be17cf21fcb774524a24a3c7ccd993cfff7d6a0f1552d43802ab1b32ad13a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/helm@sha256:e5ff9832fb1b43289ff7f593211224b3b02444d1a0830ae7a513c940a512651f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/helm@sha256:1dfc061728a2c15aec0edc3030124178564638e374a48d4fffb36706b118495b