Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 2.0.x

CIS
linux/amd64
alpine 3.24
Tags:

2-alpine, 2-alpine3.24, 2.0-alpine, 2.0-alpine3.24, 2.0.2-alpine, 2.0.2-alpine3.24

Index digest:

sha256:fa6fb198eb262a1c906f6c8fc15bc7ee27fc96c8b6d0997e8d9a988e3987194f

Manifest digest:

sha256:5226e30fdc821aed9fd30344a91f7cd530af5596c0e5e3d85fa61a6e218c351e

Size

418.64 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:2-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:2-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:d7c1336e3d016bfe83217ae68718fd9e195622cdfb6a7348601f4f8564d41a3f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:b2873686206882a24226b42a9e7942352aa85f7aae898819fbd02fb466b9a9c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:90981e7abd643722587f7f33cdd5565a73bdc027bd2dd7b9e578b73e06adc74c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:c7bcb633319df7c3525621294f0e54847abfd97e4e6021a22e75ab5c31e0245d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:141e11c191c672b47b130458dff92e6f81ec188cf33f4db897bf038ade8a17d0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:6f951d2cda9d6b800803445bf25c9c89af4ecf0847c261fd6a277ce996acb6e6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:3baee12f9a701d6cf3d1040f780a95524d64cc34b47f93d82c0f202c5fcd137b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:50ce1f6c72d5b7ccc8f9853d3615ff839ac94fe9df0385878aa91e3cb4a44add
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:dedb03a49fb5d1b37e813742a5b6612be4366fb46e344bf9483eb71cd54a2565
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:069f612f1f9c0430ef6c7cc8867b5218cce866f874a41af041079126a04ee354
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:266ee3f75c598b8d71e3a8117541bc29dfd13e3f62dcf5ea87863a2c7ad07f8a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:5e5b36c1ac633e9f7ac54b24d2c91ea845177776ca1c58b03f3183429aa62fac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:385bc78babb887b524a73e2061a1c467b87ad152b4cef785cc4a3f83a7604475
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:5a4daff4746289bcab6ce6c5c34ad501f783701ddaf351fb6134f7298b5ec79a