dhi.io/fluxcd-source-controller
1.6, 1.6-debian, 1.6-debian13, 1.6.2, 1.6.2-debian, 1.6.2-debian13
sha256:a87212cf91e63989893807987900d18c7b706db0529abe1d09afab2bdc688e31
Manifest digest:sha256:1921509e78991fe3f1390fee93c3b321d927ca40e1a66fd53227f95a37af5044
Size
26.94 MB
Last pushed
8 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/fluxcd-source-controller:1.62. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/fluxcd-source-controller:1.6 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/fluxcd-source-controller@sha256:6ac1911cbfa34c98b6a3de08ae0e65fb276e8bef7e4989fe559e4f6558a859f5 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/fluxcd-source-controller@sha256:fee2dde2bc868aecf3245f10b10a7d582d4204cd2600d8afa1bd95c30ca02dfd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/fluxcd-source-controller@sha256:972951d93a14f6c508eb049b4c1e431732926488d52c4ffd05a07aeee563eef7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/fluxcd-source-controller@sha256:682bc4d05f74d440f1aa6e44c2656bd1527706617ccc7b2d659f5fbc5e7160ea |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/fluxcd-source-controller@sha256:94b5d11a7f3ace27723468d14d2c492c211b970c7bd8520992402b136f75e1e4 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/fluxcd-source-controller@sha256:88f26ecac41febca3aff7563a7f0435a6b9989c81a8a777e822124b3069af353 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/fluxcd-source-controller@sha256:25ee08d3c13c2b2051cf141c17b3e3d414af33c45ef991ca5828fc4f6f98af90 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/fluxcd-source-controller@sha256:b41435eff82bb725c7b1644333a21c2ef2cdaab5d1597902345aff4d1330e9b2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/fluxcd-source-controller@sha256:3b6bcf10b13edd13d1229e0f7b7953fa95d28798ac4f0dfd4e3256e1f3459c32 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/fluxcd-source-controller@sha256:f63b4d64622ddfd20396b59e748022dd5e4c9db7e91fc7b7bdec948c88a1abc0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/fluxcd-source-controller@sha256:def49fb47f43a33c6f8fc198ea7d04efa79bf9369382a8a6baeb63a2b6dcbdb5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/fluxcd-source-controller@sha256:7d0c8d7ec3c19506ea31ac28b5bf9a6d1a2301930603781efc6ec616c761e1ab |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/fluxcd-source-controller@sha256:c4fce44ed644288c0bde8ef694fc9ba21e5dbef79ae9fbe1c602084ba44031d8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/fluxcd-source-controller@sha256:44dc6e552c8f57e33a67a7271d66f2d52c058bbb3322b052c5df44cd260c3b95 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/fluxcd-source-controller@sha256:642610276216cdc826c77b2639fb7256ecadcf84731be954b05e54d90eb789f5 |