Sign inSign up
OpenMetadata

dhi.io/openmetadata

OpenMetadata 1.13.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.13, 1.13-debian, 1.13-debian13, 1.13.5, 1.13.5-debian, 1.13.5-debian13

Index digest:

sha256:e8a9edceb46525a6dd7d3bbc684232cd6807b6f899b9c3538cf7029150e854d3

Manifest digest:

sha256:5d2e78259e54630664dda85c51f92776e59c2dd0a2302b2b3e4022f09d4c38be

Size

388.40 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openmetadata:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openmetadata:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openmetadata@sha256:69b73d1c568fa5be608d545708b82144a702eca6d3d670c7c8ef638da7309cf8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openmetadata@sha256:5a0d336a9ef82f871096b3bc978ea74b16a4ba2e16a6e8fff77743644b59eefd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openmetadata@sha256:b62f8dce98d5d181e02c1d1b9d7371780456484645080a9379461d5d6822cd43
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openmetadata@sha256:26106e4d377f30c2a590d3f6bf1fd6dc801016865e33e00b63f9f9dfbbb3c976
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openmetadata@sha256:95c2aa618e7bd4a5d9f5b3707f7a480e056835e53d1f97a3b3d1f7075bea8019
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openmetadata@sha256:e5cf8f3f1a216687e98a38503e5327cd87be1c0fea3ffebf119e8ed5f35c40ce
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openmetadata@sha256:a8c940514f5668c702c90eb279c0d9e2b6b53485d75223e373c92695a9f9092a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openmetadata@sha256:76afb857627f5290fefb9b475414e86c2595b749aa90580a7acfaf5fdb642f36
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openmetadata@sha256:9830fe6207084ecc88bcca096bb156688d0e6514b71d0bcdc49b69eb0861ae2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openmetadata@sha256:934d2d9bdcf752abf8f40370cfea8eb88d8bc512a9ff6662e97251f99a01cfaa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openmetadata@sha256:0e6069d870310148583286b93ab2998161bb3def0c61f0d441d1a8400f871a91
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openmetadata@sha256:502445f14db1821abd612e514f59a26ffa161f65bcbdfea2b220bc508619a8e5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openmetadata@sha256:eb29934c9bb491f4326769df261643dcd55b2af700e79c4e7df6c8169a6df861
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openmetadata@sha256:045e087928ce339bdc4add033f6359d218d9ec1afaa2aef838efc2a79d249b6e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openmetadata@sha256:9635dbd2e9753ba3c6fb0382245ab5c0197693e6b84aefe81696f8e6c9b40db6