dhi.io/k8ssandra-operator
1.29-debian-fips-dev, 1.29-debian13-fips-dev, 1.29-fips-dev, 1.29.1-debian-fips-dev, 1.29.1-debian13-fips-dev, 1.29.1-fips-dev
sha256:58f58f840ee7d8e3292a561dcdf117c93cb582f42d4b890dedcd9c6b669bb911
Manifest digest:sha256:68c86d08601d8d157f8f930b8a8a0cb55f33ab315f7fddbf3a61b467abd476b7
Size
50.14 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/k8ssandra-operator:1.29-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/k8ssandra-operator:1.29-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/k8ssandra-operator@sha256:323e251c48e52f1833bdc85b8525365254fd8f4fee015bdfa353e18a420b7967 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/k8ssandra-operator@sha256:ac58e7104fbb9d41f1f90273db0c4d3e93dd435b8f277fd558ec060655ff7bde |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/k8ssandra-operator@sha256:7a6669279442035ab09c8dfe835759693eb6bc00461fb319aff05a116f0b9a97 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/k8ssandra-operator@sha256:bec827faa3fb75a8d243a0458d6aacdbbc8e253a6c1e596cd72edb03ee0f2366 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/k8ssandra-operator@sha256:06f40906115b06cd84cc9adc8daad5d85fbe5bfc5a52a899cfcdeda1e881c50e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/k8ssandra-operator@sha256:2d18dfe8155b46e7f32bf853f769bded9f4ac615d27241f52b3bcf00e2dc238e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/k8ssandra-operator@sha256:1603fe9cb21d522c02f43bc2a4d6e8c33fd943f49a0c8a0af2b4043e3aee9f1c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/k8ssandra-operator@sha256:6e28536af407bde799e3283c4e8fff1010a4a2b783d9496071cdae8137061a71 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/k8ssandra-operator@sha256:40ab6234708c0c72572dc160f2877e62fcee3867a6b9480673048afc3f4d4932 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/k8ssandra-operator@sha256:f4f792514e4dd16195c01f4dd8df3a143d05330103a65ffe75b93cf3e5dbc1eb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/k8ssandra-operator@sha256:094530dfb99f3aaecf2a4bae574e153de64426773af9d63c61e585cf86409ae9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/k8ssandra-operator@sha256:ca6ac1976ce19e0a482746a5d1a9ee9eda0e3be0e4bafb570b3933aed0052506 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/k8ssandra-operator@sha256:5ea16a298ca1b129209d331f254ec3eb38679be14bd2abbcfe7c0be0622789ec |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/k8ssandra-operator@sha256:84344b4f9d001a5338bbcd1c90a957df57d4ff6d6eeaebb27327d5e42bffacc3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/k8ssandra-operator@sha256:1316ae334f40c0196cc9a17a5a635575fa392006d791c07368a595cc4207a8cd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/k8ssandra-operator@sha256:6c1c1cca99872f147d02881d3fbacbbb58fc5efd8d2f3efb15000525b5415544 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/k8ssandra-operator@sha256:bdf928d9cafba05debba3b0b1571bb4c1c56580b8b47c9325f084282a7c6d6b5 |