dhi.io/atlantis
0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.48-debian-fips-dev, 0.48-debian13-fips-dev, 0.48-fips-dev, 0.48.1-debian-fips-dev, 0.48.1-debian13-fips-dev, 0.48.1-fips-dev
sha256:3bae92f01ed80425d9bb904ce5506481abcfb7e5a989470ff8e6defb8fdb9f87
Manifest digest:sha256:e90f1943eb682355e88c609cb1e79366b17177800eb8e78130f748e5dbd36809
Size
143.28 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/atlantis:0-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/atlantis:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/atlantis@sha256:cdf9c457bef51de6c693f23961fb3a114c1b219bd479967939f730427b203d79 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/atlantis@sha256:4a38468ebbf5266d8486903fd999bb113f61996a79267fdab2f76c6cf9c5d89a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/atlantis@sha256:8f3ba202dd53e6a29b71dff3c55118e6846af4751e427fbf94d8e6994fb29f4a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/atlantis@sha256:df94089928ade483263218a39190c09e0d26147103e8e43f93356e36ce6c2d87 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/atlantis@sha256:f63e9f6ae628f283ae277683ca16b1924b6e214a2ba473c70ff214f8664bf75b |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/atlantis@sha256:eb0dd852ffa4e35c49d15252f582e4d07dfbaa60d5c8bcad5ec88be96167e21d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/atlantis@sha256:5cb7e44b392d71376e489402eaccb724723b6b8d98549a79db300a9a111c931d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/atlantis@sha256:28c4e1493611d20e3c688bb173da77e6a84d8958aef435b2bc96a0505e7de295 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/atlantis@sha256:3263db9036d7b948a83ca9ebc0b58a4f5d33204db6f62abd752efdd603a3e7f7 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/atlantis@sha256:a5bef5f17881e66ed95c2fcb66b01e2f37dfd513118a8229adf4f68693301c22 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/atlantis@sha256:a67969963995abd1b40b60bc50509f805d4840f054e7d2c68681b22414d4963a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/atlantis@sha256:c8392668d91f8ca8bad54cc2431cca4f315c19cbb95704c1939b8cc2b747d482 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/atlantis@sha256:022d8f7b6b6325f48255cb7053b85edd36749278391dd87a33a6b65b02a61e49 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/atlantis@sha256:73a2056696c1053117da194e37b86720fcd4b1a23db5f94473e1b2608763ae9b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/atlantis@sha256:3cb669c3091604d42bb1ce0ee68a8582a77f8dff571b9112af1ced5c4939cf70 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/atlantis@sha256:dd7babf9df7078970ce30c6237784823aa510b7011dea3c1c05824072a18a129 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/atlantis@sha256:670d21af4e7a29f9ea2772968d820471a785cec7fef57a01ccc89c0251d2d605 |