Sign inSign up
Atlantis

dhi.io/atlantis

Atlantis 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.48-debian-fips-dev, 0.48-debian13-fips-dev, 0.48-fips-dev, 0.48.1-debian-fips-dev, 0.48.1-debian13-fips-dev, 0.48.1-fips-dev

Index digest:

sha256:3bae92f01ed80425d9bb904ce5506481abcfb7e5a989470ff8e6defb8fdb9f87

Manifest digest:

sha256:e90f1943eb682355e88c609cb1e79366b17177800eb8e78130f748e5dbd36809

Size

143.28 MB

Last pushed

6 hours ago

Vulnerabilities

4
12
1
12
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/atlantis:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/atlantis:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/atlantis@sha256:cdf9c457bef51de6c693f23961fb3a114c1b219bd479967939f730427b203d79
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/atlantis@sha256:4a38468ebbf5266d8486903fd999bb113f61996a79267fdab2f76c6cf9c5d89a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/atlantis@sha256:8f3ba202dd53e6a29b71dff3c55118e6846af4751e427fbf94d8e6994fb29f4a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/atlantis@sha256:df94089928ade483263218a39190c09e0d26147103e8e43f93356e36ce6c2d87
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/atlantis@sha256:f63e9f6ae628f283ae277683ca16b1924b6e214a2ba473c70ff214f8664bf75b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/atlantis@sha256:eb0dd852ffa4e35c49d15252f582e4d07dfbaa60d5c8bcad5ec88be96167e21d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/atlantis@sha256:5cb7e44b392d71376e489402eaccb724723b6b8d98549a79db300a9a111c931d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/atlantis@sha256:28c4e1493611d20e3c688bb173da77e6a84d8958aef435b2bc96a0505e7de295
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/atlantis@sha256:3263db9036d7b948a83ca9ebc0b58a4f5d33204db6f62abd752efdd603a3e7f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/atlantis@sha256:a5bef5f17881e66ed95c2fcb66b01e2f37dfd513118a8229adf4f68693301c22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/atlantis@sha256:a67969963995abd1b40b60bc50509f805d4840f054e7d2c68681b22414d4963a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/atlantis@sha256:c8392668d91f8ca8bad54cc2431cca4f315c19cbb95704c1939b8cc2b747d482
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/atlantis@sha256:022d8f7b6b6325f48255cb7053b85edd36749278391dd87a33a6b65b02a61e49
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/atlantis@sha256:73a2056696c1053117da194e37b86720fcd4b1a23db5f94473e1b2608763ae9b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/atlantis@sha256:3cb669c3091604d42bb1ce0ee68a8582a77f8dff571b9112af1ced5c4939cf70
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/atlantis@sha256:dd7babf9df7078970ce30c6237784823aa510b7011dea3c1c05824072a18a129
SPDX SBOMhttps://spdx.dev/Documentdhi.io/atlantis@sha256:670d21af4e7a29f9ea2772968d820471a785cec7fef57a01ccc89c0251d2d605