Sign inSign up
LocalStack

dhi.io/localstack

LocalStack 4.14.x

CIS
linux/amd64
debian 13
Tags:

4, 4-debian, 4-debian13, 4-python3.13, 4-python3.13-debian, 4-python3.13-debian13, 4.14, 4.14-debian, 4.14-debian13, 4.14-python3.13, 4.14-python3.13-debian, 4.14-python3.13-debian13, 4.14.0, 4.14.0-debian, 4.14.0-debian13, 4.14.0-python3.13, 4.14.0-python3.13-debian, 4.14.0-python3.13-debian13

Index digest:

sha256:39d31e85aec0ee9e0e68352341e4b06966dbe86bc9bf62c54ae94b95e747b5fb

Manifest digest:

sha256:6d3fcc44e7fbeea1f01db65b32b05f7424eefeee299dce9c01c3000ece9b9799

Size

125.69 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/localstack:4

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/localstack:4 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/localstack@sha256:be67f7af77fc7c00381830f791a783ba7ad181b5e3bc28d4892275cee7d382d6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/localstack@sha256:6f4ae452d9483bf5333d6abb2b1c89e6c671c95aaa8cb1303623b55aacb4f231
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/localstack@sha256:8d5e9decf1ae47c6d3b0d3d5db7d2dad5424fee382d25735f80941393379fd9d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/localstack@sha256:f55a5d072a6e1324fa6f01ca278873b78db622836a6b2fa9ba52e0d419dbf2ba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/localstack@sha256:2e142f3fb6118c8cd9301b69aa946a2e973558c35164565e20bcf904529b6014
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/localstack@sha256:d5877ac5ddb81e90a090ec20277ae8875bcaa98a4539ae2feb926b640ee91de2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/localstack@sha256:ca7e463bcb7967a93207992f5b8747723201be46c8258b2f9ce54198fae6c693
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/localstack@sha256:25fccdc35d15335b32f7bfa0cd3983e156882859bc66e69e7f76fc91e9121406
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/localstack@sha256:ca98e7b600bc362b66ea35004542db1c3560a7fc1d707792c5fc255c9a96d6c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/localstack@sha256:ccee5b096df0a8ab7b001a9fa2a5cb7de001940886d3b05b277fc012c76c52e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/localstack@sha256:9e3eeca724e220776a0c7c19763e6ec68932c6ccfd54f56fd947f247809d61aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/localstack@sha256:b0d71d2c5d3f41468efc3b2c2f86af51efe89ecdebafd1b9a6cbe5974b8331d1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/localstack@sha256:65fa302cb0e49345714f38fc339e1a9b2fc114a7353256c5c60636ebbdd93063
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/localstack@sha256:6b449546bf67db5fdc29a3bdc269960fcaa74846376ef03a8d4567a4d275f5e6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/localstack@sha256:704e3a9e50d11250d8a710ba0dd5719c43d6ae0207f165e41bc808b0878615dd