dhi.io/atlantis
0-alpine-dev, 0-alpine3.24-dev, 0.48-alpine-dev, 0.48-alpine3.24-dev, 0.48.1-alpine-dev, 0.48.1-alpine3.24-dev
sha256:3dc260f062866ce14cc6b286550f2fbdc7124aaaab7588a1484428b18279dd24
Manifest digest:sha256:689aaa383613b70a87ade3968c1057e4aa45ffc6d2a73413d29897e89961a972
Size
110.03 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/atlantis:0-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/atlantis:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/atlantis@sha256:4dd358442eb570bcaea4c7022a2e3f85ec88a921387b28d8187057f9e17765be |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/atlantis@sha256:25979ebe2dbe21273e1724b7a98afdbe3275d93c8ee4868d73a938d9b4f2802e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/atlantis@sha256:ab4f8da2c74826ce3eceb793791d598d93d08d561f6be39aaead24b200c833a4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/atlantis@sha256:d792f8d18909af822ceb7a36be6881ca78ec72234bdf0f78c26cd6d759a5f0de |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/atlantis@sha256:7b4ec8cd87ca1a45bb175b323384ac1969d7208f35005e6aec8fc00d44371c29 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/atlantis@sha256:ba13c3c7d4c62c68d90f7f6705939c8acf22be059294762d9ebf43ffa2532866 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/atlantis@sha256:7fd868160d9e0ffca1935482e8044fd0347b36a2fa15f5ea1e2ec0a1db5c21bf |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/atlantis@sha256:3e732625e01de3c94697aa6030f7feb2a15515332db31f59661a7905cbcc5ef9 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/atlantis@sha256:437bfa0f7b4f48f3164017837178f8c631099e86e354aff39c3e71b061dcfc37 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/atlantis@sha256:09caec55ecdc4f848d5898e31d22b654eda561d18a3bf742824c71286617152a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/atlantis@sha256:9f4272d204ffa75aad1adbd75cbee5459eb9837e0dc5f9a00f2e8b88b2da8ac7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/atlantis@sha256:2ddf2c4dced2c639439b1b0531da423eeb9b22e827559e5b8251f0d949093a1c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/atlantis@sha256:ab5094e6c185aeb96c3d43b6d81fade857abc95ac269d739ef168ec16738fe3e |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/atlantis@sha256:f465cfdc2cda351bf2bb0b952200bb58cf9dc291d475adbe3bd8c05a474d5055 |