Sign inSign up
Velero

dhi.io/velero

Velero 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.18-debian-dev, 1.18-debian13-dev, 1.18-dev, 1.18.2-debian-dev, 1.18.2-debian13-dev, 1.18.2-dev

Index digest:

sha256:c925902683bb1665b45ea0a3a1a3dc201897e2f385ecbcc9333d5ad0ca60117a

Manifest digest:

sha256:8e985774866ac542022c9fd78b2f0ff0668d8df1d77946334f5ba0b5a641ce8a

Size

100.84 MB

Last pushed

10 days ago

Vulnerabilities

1
8
2
5
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/velero:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/velero:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/velero@sha256:c5d6b620c57819384cd7a6b9fe570ad6b9c299f21ff05ffdd2e9af67ac34689e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/velero@sha256:cdfbda7fdb157b92b0bd4bd71d68e418ac442528220c6595cd2cf70a6cffafa0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/velero@sha256:ad6fffa684562e54f692936576e4d7059eb2413a4b3474c4cef1b6adcda724f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/velero@sha256:61896555e7b40adc8b17f7e88417054304b419f3500e1552207836f35f46ea57
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/velero@sha256:64bb2f45a6b6710c6391aa65fb62d7915e9157ec72d107d6092535eced85ce41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/velero@sha256:74e8090a4d8ba2d5b57aad67a0df387c1f4732dea18ca132ecac7ad4accd9759
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/velero@sha256:96dec48401cebb7191436e41fa97f19270b42d8321a235f6e770c90edb6f9a3a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/velero@sha256:6c46d0f267d26daa60de504715bf6bf36dc80e9e0d22a889593a70115a000ff4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/velero@sha256:415a807e4afc22f471f0066ffe107f7f146e01ad16b4573842d86cb579c9d052
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/velero@sha256:e19e6b67f988e2dccf088d2f1cdcd10a2b305b5ef0d7ecd62c0c0aaba1cfc952
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/velero@sha256:950553a198a1276a27cba6e10b657031055adf08a12cf31b8a48624c209c5f6d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/velero@sha256:61d25f3237980b5d3bd68ad3eca6fe5dea30d7bff7fc74a2bdb20007cd7736fc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/velero@sha256:23adb21d7d35d00428ef4fefd2a7e6e94946ef1bb58b5b2a8cea398b224796b0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/velero@sha256:3d68a76597bab46b7b6114387cd3e545e658a3067fd213bd4b04480cfa152256
SPDX SBOMhttps://spdx.dev/Documentdhi.io/velero@sha256:642af069898da620d4f4da4de20ebb6970e0066523d2bab41be044cbd0445d9b