Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.13-alpine-dev, 1.13-alpine3.24-dev, 1.13.5-alpine-dev, 1.13.5-alpine3.24-dev

Index digest:

sha256:a67aea26d371f980e0925892912d93b1d7dc544c188cfae8764cce15053e2669

Manifest digest:

sha256:9095c4edcaf1820393f017f894789c69aa3165034a8c2f5c16156dc7bca3ea4e

Size

382.03 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:d685b00c95dc069d6f45eb1d934da49feed4990d4e02d2bda45dc31f9967907b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:45c065df650db7bc7c75f62f421f0dc04d8a982f4d7e1e1b243426c47c8ed7ae
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:58998db12a135bdebd0c05dd76aa67bcdb6142469236356022e56534e5d89cd7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:c50f129c4e2c783899aa51a2b30c0abc80f67511cc8a2f4ed5869762790eb790
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:85f5fcf99af47b61c6dfd6fc8d7e75137e565f04cf95e021891e78a3cd7fa867
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:d6e692512fc8321f2a59cfa9b0567513fab1925e0cbaf31c93621469744a864a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:84e642ab10dd2e7ec964a7b46209d1f087e91b23ccadc76e8d14e87579a70485
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:88c78f2b9ff339d65dd7bf17d8a60123c327d2a16d567e96009f49c4bc95a4e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:d0b061696cb74af02d11737b1492fa1d57c0511cde1a2c52a1abfccf740fde99
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:d64128425307c3e13b9d12cda49e46270ef5f1009208900952639675e16fefe3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:8fb9f1ba7e56cd2ae66e812db835f8f397d3fb149cb249ee205343b49fae3cab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:85910e7e15f200f35d77cf63b48d724a7162ade428c278bd322057f6334930cb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:e36bdb7bd12958a71d66bb1b89cffbed068dfb0271712a994ae7a27dc3d6758d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:7f8c34a1afa8f12d46b452d67aab007995fae996834696722b14db40f89fb5ea