dhi.io/netbox
4-debian-fips, 4-debian13-fips, 4-fips, 4.7-debian-fips, 4.7-debian13-fips, 4.7-fips, 4.7.1-debian-fips, 4.7.1-debian13-fips, 4.7.1-fips
sha256:7646dccca12975c66c48b88eb359ebb7bfbb9dc18b252063e620e57cda79e1de
Manifest digest:sha256:01dc89ee58c266d92c510f3d1748890fb0af34671f6c7865e7879935102043de
Size
120.79 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/netbox:4-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/netbox:4-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/netbox@sha256:230f2fd697ff9598579b60fab05e192b87b5a613d67fc8e7b17d31b6c61e3808 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/netbox@sha256:eb56a859be8b88a9d4eeaa72ded87fb4482fb434ad2601ea19a75a012042764f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/netbox@sha256:aa4639b02f7f754909a81ec390e68930e9d4e66eb82654257e2312ab9a587e96 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/netbox@sha256:ef9f900edede65cbee041a4a43e1c2582797a25f0ebf0f99e0d8c999e8544b52 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/netbox@sha256:52c654f32f6ba5bcc9e8da22ec0ec7cdd975c8ccb1464b8b6f35d16cc930c6fb |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/netbox@sha256:a8ba26e7fafb80cdfc1c38c33d93e53c9b6ecc4cc031ddafe92206bc5901969a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/netbox@sha256:4562b150ff032c4ac81c8cbbbd969b11aad702946679b25af29efcd5d02de1f1 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/netbox@sha256:da0691cd0a7764f664cce918af2f69646aca4ea8f1c64ab8d5faefafb9e5c9d7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/netbox@sha256:06a1245414e5c61a3cd28fb16b82d7fa0b0f56be161b4e764ddd3ba7d59dfc59 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/netbox@sha256:85ce79b792b9e30ed9a0bb794728ebe30773ddef2e94d6f9f61677961e75e88f |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/netbox@sha256:3789a756f181d61172e1f84a75edd7688ca44557b5200b8650f516aab6297630 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/netbox@sha256:0f9008380e110788f2e4049e654e99d7093df2e95501fdc40fb32fe993c6d8b6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/netbox@sha256:9b6395333cf77f930664e08c32f42d205bb58a0fbbcf06db2a671e173525d2ae |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/netbox@sha256:ed4ee404ebfdbb4e78759b9e6fc481006b505a8eccc205859188b462f240b79f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/netbox@sha256:c05c54aa9edd5496f20689856d6d0ad2b3da05c563ad421fa39fcbc0c5b39b23 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/netbox@sha256:285e57e0d58634e33477a9d7cfb6424ed577384376aecf0393fd6baff9dc74c7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/netbox@sha256:6cb34b8e07df3760ca730c75ce4204bc6ff89338883056a66c54e54db2876bff |