dhi.io/virt-api
1.8-debian-fips-dev, 1.8-debian13-fips-dev, 1.8-fips-dev, 1.8.4-debian-fips-dev, 1.8.4-debian13-fips-dev, 1.8.4-fips-dev
sha256:1c4d1f2be840297cfdd21268f18d2a3f9aa09d2c55bcc42e60d8c994a23b6a50
Manifest digest:sha256:247691f63678accf1576f36b091f31cf380325f8ae2dffd4a2097e0598655db7
Size
57.85 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/virt-api:1.8-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/virt-api:1.8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/virt-api@sha256:8b9d450c7212469e68eafac5f98531021ad4e8b9ca40673e07e09f52204381de |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/virt-api@sha256:194ab2fac2d8eca93ac894e6c24350ef25c8c6201b670ff81e7ff6f9dde0ac9e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/virt-api@sha256:864abba41abde4e552b54f69f508df5049fbcf6886e16bf30f84bfe2b7d354da |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/virt-api@sha256:5fc76ebcbdfc3ab07a73ce6aa4d418f189092aec46a4c402891210b0936600e9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/virt-api@sha256:50b7f1232be604238c87a81ffe82578ac16fe1c8a93ec90a6f6dec08fbb23ae6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/virt-api@sha256:fdbe03f929337b57440ca0e860b9b10e14616080f5c8a5584bc7d1a7099f105d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/virt-api@sha256:018e0ac120f42fcb6f79588f4cdc02360cb3b75c6597274f02c35a6fedbfb836 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/virt-api@sha256:7d3a6c6349a86099e9c7933445b260ca05e92b09e9e04f80d46f2195a9ce37df |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/virt-api@sha256:9c188f927a7bbd156247d62b8332c37eeadb7ca1b82916f281789ae7b79df968 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/virt-api@sha256:80a9418dce3c1cd727e7445b154b5742f96873c00546c18b3a0896f5251c965e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/virt-api@sha256:1e7f6a78c6553f28648292124621898a160213f6f6d80a620cebb619b9bc3f72 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/virt-api@sha256:2b17b877ac2f81bb7acc6f1c7a4bc4b9d972541501c23924a9da9ac0c3190b99 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/virt-api@sha256:5725a8b7f441dcbc06b8f864715aeee7ec77dbe92fde13f122e8e8c2bbcab18a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/virt-api@sha256:e92ac2ee8ef2046e5c9242afa15c0636b862d67b58fa50a468e092f95e3c5d57 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/virt-api@sha256:0033714e83f9d0f615b53086997fd08bd97e0d01524fca3aff58a463acf63b04 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/virt-api@sha256:eb646748137d7af86861847715e05f82811d5dc785b6ac1889bd516baea6922f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/virt-api@sha256:1c3aad13a9aa8ed891185d01772c320c11f82a3bec641c1aefcbcce262d43d01 |