Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.6.x

CIS
linux/amd64
debian 13
Tags:

1.6, 1.6-debian, 1.6-debian13, 1.6.2, 1.6.2-debian, 1.6.2-debian13

Index digest:

sha256:a87212cf91e63989893807987900d18c7b706db0529abe1d09afab2bdc688e31

Manifest digest:

sha256:1921509e78991fe3f1390fee93c3b321d927ca40e1a66fd53227f95a37af5044

Size

26.94 MB

Last pushed

8 days ago

Vulnerabilities

1
2
2
0
9

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1.6

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1.6 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:6ac1911cbfa34c98b6a3de08ae0e65fb276e8bef7e4989fe559e4f6558a859f5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:fee2dde2bc868aecf3245f10b10a7d582d4204cd2600d8afa1bd95c30ca02dfd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:972951d93a14f6c508eb049b4c1e431732926488d52c4ffd05a07aeee563eef7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:682bc4d05f74d440f1aa6e44c2656bd1527706617ccc7b2d659f5fbc5e7160ea
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:94b5d11a7f3ace27723468d14d2c492c211b970c7bd8520992402b136f75e1e4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:88f26ecac41febca3aff7563a7f0435a6b9989c81a8a777e822124b3069af353
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:25ee08d3c13c2b2051cf141c17b3e3d414af33c45ef991ca5828fc4f6f98af90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:b41435eff82bb725c7b1644333a21c2ef2cdaab5d1597902345aff4d1330e9b2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:3b6bcf10b13edd13d1229e0f7b7953fa95d28798ac4f0dfd4e3256e1f3459c32
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:f63b4d64622ddfd20396b59e748022dd5e4c9db7e91fc7b7bdec948c88a1abc0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:def49fb47f43a33c6f8fc198ea7d04efa79bf9369382a8a6baeb63a2b6dcbdb5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:7d0c8d7ec3c19506ea31ac28b5bf9a6d1a2301930603781efc6ec616c761e1ab
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:c4fce44ed644288c0bde8ef694fc9ba21e5dbef79ae9fbe1c602084ba44031d8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:44dc6e552c8f57e33a67a7271d66f2d52c058bbb3322b052c5df44cd260c3b95
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:642610276216cdc826c77b2639fb7256ecadcf84731be954b05e54d90eb789f5