Sign inSign up
Azure CLI

dhi.io/azure-cli

Azure CLI 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.90, 2.90-debian, 2.90-debian13, 2.90.0, 2.90.0-debian, 2.90.0-debian13

Index digest:

sha256:cd5c6a60716a374bc5ba54af44bf1a4a0c2b70e23f3ebe75e9c913ea8f1c55ae

Manifest digest:

sha256:3234babb0d8a2d7aaa7f41835fd67de1eacaba1d4e38c3c7b86d78e14647d6a1

Size

37.44 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
5
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/azure-cli:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/azure-cli:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/azure-cli@sha256:ea8c7e4f5fe5b3d5c867f9eb98f9948ace76e790f277f81866fa55510808b838
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/azure-cli@sha256:9f6dc800c37fdce89fc0d4d35eb7d132fa549088a22597cbfd8683609d8b8341
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/azure-cli@sha256:b6ae395b85c74430eea1710488dc2413e5042b0431a6307d792db2e070359063
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/azure-cli@sha256:d62fb9daa5a28b067a3f6162521d9d41067a5c0632ac4e5f0dc5dd822190d192
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/azure-cli@sha256:22eb57ff755b39df5ea50de6fcb924b0a07875522662abd6d1dae4888f611af4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/azure-cli@sha256:e8836c7c03a028adfb91dfb2c5dbe54b7e147fc6880558c326dc3851c4468340
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/azure-cli@sha256:6b2a76c94ab8bcf2d4b07a10f1d3703aa516b749f3972caa112451dbe67107d4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/azure-cli@sha256:def8109295fb65dc8f8631e6d5be9d3bc5547c10459c0a02d9af79b48cc0a688
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/azure-cli@sha256:e0be724e1b5f7ec360d8461e0c4ce0c40085cd9887153a589adda999c8db392f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/azure-cli@sha256:bd345a1773d06d2b1265dd812c0db4fc87a31dbe01f70d5d8980b48d02a2b3ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/azure-cli@sha256:408940d188858846a0cbf925194d6c7a5bd557e935d2659afa6e25177eb74249
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/azure-cli@sha256:832728b3385840ca5bcb0b35601efb8e7b441cef433078d41895c1fbfb0a408e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/azure-cli@sha256:730208d4890aa235bfa6ce04b04d1d92f49058b0f5a975710bcdd7119bc9340b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/azure-cli@sha256:a6eba2feb4a770df9cfc1941702d41190b2c0df9675fcf2356f3c5ddf9f74d1f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/azure-cli@sha256:0b124c5dd2dcb083ebc651d1be156dbc80dc527250d85322639849837572fa57