Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x (dev)

CIS
linux/arm64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.2-debian-dev, 2.2-debian13-dev, 2.2-dev, 2.2.3-debian-dev, 2.2.3-debian13-dev, 2.2.3-dev

Index digest:

sha256:ae36ade5835531c9c62f41c8582fbda91973c401944915a2b2697831c2acac99

Manifest digest:

sha256:3046bbfa85a546e61bc5b16f1913e5ef75f01057667c29bcc0230090678524fd

Size

45.88 MB

Last pushed

47 minutes ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:3d826f7ac03c4b78088fb5e132f2aee18352266b5ac56f5abca793b35cebc16e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:e52b21b62678e1a43b15e21bb10e157688591f3abfa04cae1a1a7d5c5851fc7b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:a573a09e69a4e213f7cd98a0b4e3e8b209c112d99e68f49d3d322b2713f7d45f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:3af97b38b43fb5f4039381e241e75f09452328c59385e52739173c17db4a0437
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:a351a51dc071d317fa32ab756573144d34c1fea0c10b3e3a5a21881cc699848e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:efe24e966fee5ca16645936c633166a4a35f44e8fed6c30bf2ce9c9891cc9a4a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:0fbbeff84301bd352294e294232074ae15a48d449c1142d940b5f3cc87f6e1a4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:e52595c5a06468dd2a741f8dd2ccc68917fb0f361e83c7c96b6343af9c86d0d4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:2638ef5c1fe1e9dbfed58c5026cb81ad10560f4873d8ba32041434adf8f8f737
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:b415938b1be932ef22ba6df04068ab7a8e266339cbadc3cd0e6bf19b10521126
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:45cd2d4e9ebffa4c78fbf554635a172844126f80e32584b84f32981bcc238511
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:f0be60b185b9f856d807268e47b3fdcd5a8c2114d86d7a80b41bd1ef0364984f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:a90abbbb46f0f31be68017417d3d311166e1a703428ad768c7dbbbca35583f87
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:1c48ada2b0f4360c40d6506d9291aeb80dedf4b67a647edfd5a88efa62513cbc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:5e2d81694b7854fd04cdac679c2d1fbd7b36729dbae1fe5fad6c5d2423977b20