Sign inSign up
Zot

dhi.io/zot

Zot 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.1-debian-fips-dev, 2.1-debian13-fips-dev, 2.1-fips-dev, 2.1.21-debian-fips-dev, 2.1.21-debian13-fips-dev, 2.1.21-fips-dev

Index digest:

sha256:cdb1cece20f47e7e207038209958cd53eea97331b42cbd3e2959036c8b776526

Manifest digest:

sha256:f71c8d7f498bdab10e76233a18992eea3e240d75e39526d841f1d5c5a849b3af

Size

72.99 MB

Last pushed

16 hours ago

Vulnerabilities

1
1
3
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/zot:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/zot:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/zot@sha256:9eebc630dbf15dacacf6e77828b6c843884a0c8436d948f36cda428fb4a0999c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/zot@sha256:3d3cee571a88bbcbefada47a8b215027a31230e4c243539c33305e71c4efe3a2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/zot@sha256:477531844b460b5761fdf48af865aec15fa0ecdea4d61ef52cf7cc6ae9a343c3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/zot@sha256:8c21553f94ea23315581819f600a410aa6debb8de7e9da9d37c1549eea3c0300
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/zot@sha256:b6f5530eecb90e096ba98eef8240836a2971ab78b8428dc529ed91700fa63147
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/zot@sha256:e8c08eff0769396229fc9ea10ba76c1b3780985e8b9fe2e9ec19d2a472065e81
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/zot@sha256:e1973fed03b95a4f4eaa60ce40a483feb9ab6e3c8d574b34cc11278c0cf33113
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/zot@sha256:6274715dbd17b45005d2eebd2c6922b8133a1c239814654b839d20079ef7aaf6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/zot@sha256:d7291b50c2ec68ab2aca7523c10941649a4e9e3cf994f9ea410d6105d82ee0f0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/zot@sha256:ce085460cf4526e31230681ea62c0bf85e4f3047e836160766679d009c158b62
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/zot@sha256:958474caa7c739e7c6f341dda565ca1b5e71a9fa4b3ded84decdcce33aa1dbf0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/zot@sha256:8614197e971b68b3911f8dea9ef06ad526a7eef5041874115d8f228c53b23660
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/zot@sha256:c1d8fb952245d1696d2b2b76329ae25b313d791ce56f06fe4aaceea4f88e7984
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/zot@sha256:d22796e5ba81b1b086c60cc5ffb2f39ec72dd28a7a2dedabbf5bc183f89cc789
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/zot@sha256:2d4e7551e49a1470e613dd88801436901ca13ae05c273a4a4f898b439cfc351a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/zot@sha256:de5c731b0cc2bb0b1ece68bc186ebb82ee8e5c355704103be0bf503a1f320507
SPDX SBOMhttps://spdx.dev/Documentdhi.io/zot@sha256:e60064e1feb02726c2a02dd00ed87320593a7aa4909e8556bd9a02a17479d34e