Sign inSign up
Atlantis

dhi.io/atlantis

Atlantis 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.48-alpine, 0.48-alpine3.24, 0.48.1-alpine, 0.48.1-alpine3.24

Index digest:

sha256:92b43974e20fd5be7c7a41b3aa4f66ba92371dcd37efb9ff86bc50e7d1f46dc9

Manifest digest:

sha256:8779197df131b1adade9990afbb1eb1f9606753ea6f0c65a2cd40eb410eb1018

Size

65.59 MB

Last pushed

1 day ago

Vulnerabilities

2
8
1
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/atlantis:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/atlantis:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/atlantis@sha256:d5419f4c050f7c05be672e1becc4c72a5df1feb18dc499638252b83a178b9e7c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/atlantis@sha256:c7087aacda3081868a20225950758c16f75996e9849b33359c66d66568104d02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/atlantis@sha256:ba1b1ca339401d3666d7500b73b095575fc593ae984d427c29ebe3a7aeae18d3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/atlantis@sha256:4a04b747cfb95a27b6440ab4f744259382f5d992b4c1b9f7412762ab65cef08b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/atlantis@sha256:5404d06cadbd286159e4ce13b7e9c5ce8ab88ebd2ea518b2f2ae6b37ad3de2bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/atlantis@sha256:994699772d154d613e355dc88d63aa34a814b8ab1c6802550c3d6dcd4383c4fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/atlantis@sha256:12176da526e19a2fdffdadec70f959df6ef94c4014fcc4b20c2f3ea5bb693029
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/atlantis@sha256:e4bef3bbf25c46986feb1f09c67a3ad5c8efd0d16bc9c87e5083bf28e4b8e9f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/atlantis@sha256:d2678bef06199baf3efe9eb1629e3eecf69028969d1479fb4a7dfd14f00c86e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/atlantis@sha256:01df7be736e467de35f32ddf01666a2533666413a4f6edc9cba002c5a4a8197a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/atlantis@sha256:bb949af14f23b6b8caf82465407eab665805ec8b0c33192c86a25210ed3416b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/atlantis@sha256:45dd0ddf2b046561fbcc3b3397b4bf096c8ca196e4ce266334a46a453b730bec
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/atlantis@sha256:94e9f3e5ffa3b1352f66083fea213c6e8508ad902c599c7871e6dd231daabbef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/atlantis@sha256:475d38b88bd8206efeda8b870c4d4782db4b1e393e3743cb9722d3ada68576ef