Source Watcher

dhi.io/fluxcd-source-watcher

fluxcd source watcher 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.2, 2.2-debian, 2.2-debian13, 2.2.3, 2.2.3-debian, 2.2.3-debian13

Index digest:

sha256:16159e43e9eccb7f39301fb037bd74d51577efa57559408a5de3a11d59052750

Manifest digest:

sha256:20d3b3a842027f047f4de4214afc4c6004ba68a5ef7d04bbe42760526ebe8177

Size

13.58 MB

Last pushed

51 minutes ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-watcher:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-watcher:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-watcher@sha256:471941cce838f9dd0c2fbd3893fd8f4c63c0790e9eb928bd36e03ce03d36a384
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-watcher@sha256:4e443a43f86688eb889bfc7a23f420f42f30bd3f41c6147e44555476425db224
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-watcher@sha256:b8de2db8c04c37119485356dec436ee17972be7586c335459308f2cbc96fc34f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-watcher@sha256:c4a3074c22b49460a3d16113e94c61b8e450ebd8f056f1fe5be71e7d51310ba9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-watcher@sha256:ff6cabc321f16fb0a47fba7684e1dd14ca1f93abc1e59220dcf9b36215a49702
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-watcher@sha256:dcbda59dd88022b7cd0505ecbd19c87438178b895f6c8f842e83e850420096ab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-watcher@sha256:3c3460c1c2c449b897d58048798f25d6527cd4951e36efaa3e22d6ec492abc0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-watcher@sha256:ff7f493562ac854937c090ad56159d9e536bb1385cd0db237845cab20e7a1b96
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-watcher@sha256:f2bda74edcde2f0becc30acecc2caf3fea98aac5e1314030c84d092aa356622a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-watcher@sha256:9a8a053fcf73b9c726d3ba8bc96c1e20d49983f0537166bdbe38377f99fab4c9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-watcher@sha256:412b8cdbdbc3f19c201bd3c67f90408ab5d19b00c61b2ea9fc630dba9adb08f8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-watcher@sha256:9746101eb08748d9aacbede9ee8055da29b520eca078dd5b0ae689896b970214
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-watcher@sha256:ab3c8ce1712edb1e658ff2343dd7f593a6e6c99a1e208a571529f7ebebfd9c74
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-watcher@sha256:016a5ca3c88c730c1041c56324be18477d5ce67d1f69ae908315febcfda35278
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-watcher@sha256:f54010b0052100f4fa25f72492cabab317b30d6ad0d2447e049c0a83d9855f68