Sign inSign up
uv

dhi.io/uv

uv 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.15-debian-dev, 0.12.15-debian13-dev, 0.12.15-dev

Index digest:

sha256:410d16abd4cfcbbfe3dcb3878ffedd95121f37f16e698e220fc2c88c19310084

Manifest digest:

sha256:e0ab701cb6c64db5cc444b9fcc74567dc54f5290b4ce2d0635a4182a14ed7cb0

Size

60.52 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
1
3
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uv:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uv:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uv@sha256:0d9f0a5f49665f861440312d3b79515908b17f2caa01e09fa5721fd40bb34111
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uv@sha256:552e6db093974a9dac5b1ade37857e65380875b53a8922d3320d2b45636556b5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uv@sha256:ab31451a1f470ba8967c0e9699b74ef0f7192e780b80d37f3d00c12bb1f54987
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uv@sha256:fe426499709e1801c99216bc409123c74c83bb99ffb63cca926f6f8e340a0f64
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uv@sha256:9001a6d2776f4a24b223371b52f0966993648cb99439b2238fdf7768c08945e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uv@sha256:78a52c78bf49146325840c6e95dac9f971d2ac8d33f3f14be80ecc66371d6f2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uv@sha256:436f9b4645bfbed4117ea150909061847b958c1d3ed210b7e0fec6355e09afa5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uv@sha256:167d00da24d072e96d7e674554b13ec3263e05be4c2e1bba4fe644394d93a64b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uv@sha256:5d4e5dd25c10d0c1f4ebbaca11ae3fdc5f6e0e6bd497c2fcb0902f655f88f292
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uv@sha256:0d5a1741dbcad059db9ea2713c7fbc81fa92fb36e9a79f7adfcf5f1d883d00b9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uv@sha256:1ad31adf1e3a772e3cc22de7f528c0a19361fb28fc4e1ca69c4b0e0564631ff7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uv@sha256:f8ef0dc562d7791746187f29f14f9bb8abd3ca809f291cad79346ba136e21ab1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uv@sha256:52845a0081d9f17b9df38e80c521fcfd06841e1cc3cae9e90d86780f12d3d05e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uv@sha256:f0afbfc8661bebfe2288a7f880c3ccbccdecf1e70e6fdbae9d5a3f3cd3ee0871
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uv@sha256:c0bd88b00cf9c5f162d713e44140b3b1e581d2df451d894e76ec2d02e89bd9d2