Sign inSign up
k8s-sidecar

dhi.io/k8s-sidecar

k8s-sidecar 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.11-debian-fips-dev, 2.11-debian13-fips-dev, 2.11-fips-dev, 2.11.2-debian-fips-dev, 2.11.2-debian13-fips-dev, 2.11.2-fips-dev

Index digest:

sha256:7677e48defc58141f39039196216d88893473e78dfc726c8ac563a22ab3c54db

Manifest digest:

sha256:6c634dd103a20f534567884d4b944350838fe66b382caf68b72d6989b6c9fcf9

Size

40.86 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/k8s-sidecar:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/k8s-sidecar:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/k8s-sidecar@sha256:50973c754cadd5bea4626a69f2619d53b55e6af56b2fcd74ba5acd5d701472a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/k8s-sidecar@sha256:75cc80eb77cf3658ba5ff8130ad8f7a3cd67ceaadf9e8c33dfc070d00e6db5f6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/k8s-sidecar@sha256:4835c4b92d7bef3d2ab2f90a7e3223d5e3f84c0b8afc1a1bebcc4e001ddf2ff1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/k8s-sidecar@sha256:6af64c696e9b0dde9fa7b12f5b84e7a9816edef949956edabc043ff6349dc675
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/k8s-sidecar@sha256:be3e024401fc41cfad5850485fce9a79c9477e1eff0e514497f59b108e54e895
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/k8s-sidecar@sha256:0f3af1ea902d754b1277a2d8e3ad88be71fc4f2a88d78687a21763d9cff728d2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/k8s-sidecar@sha256:052943d47d72447fcecd763f746e3ccac1786c591c2947b1ebf7fa68169cf104
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/k8s-sidecar@sha256:02edaae1a2bc2f15932f1bbd541f8fe3c5ba3513a92f279632c7b7ca10d5dfb9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/k8s-sidecar@sha256:6b1051e476a61b0a87e878eb164e5d1960e21373776f3e356923a1f5f05f5666
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/k8s-sidecar@sha256:c0d2d5f237cf25b75074443915fbd54a0f46d76900bb3f140d6cfe74cf717fa5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/k8s-sidecar@sha256:380ae19abe1be1628c7e5809a154ea7175c6c88072580a6d5a5c2f85d7ec2f63
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/k8s-sidecar@sha256:5b7afa34e469857143cb9e243ea0a71f24bc5fff5aaa58679c38fe60ead376a1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/k8s-sidecar@sha256:dffb24b26574518fe8a6e69454ad3374daf22eccb10876d72269ce87a6f7585a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/k8s-sidecar@sha256:9ba12c5a9c25796d320db6d92dc6da2d3d22254805f2e42883bfb14b501d3779
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/k8s-sidecar@sha256:b45024937effa64e865f423197da3f7ef2fb7a75acca2ccf5ad997586ea069cc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/k8s-sidecar@sha256:e64a6459f83c564b34c3540247b7b5cc8767aa35e308cd170971701f03d60fef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/k8s-sidecar@sha256:759d9d2a33c7c1f63e7fa2231bef6437392050899cabb47ac841ff385b9f698d