Sign inSign up
Source Controller

dhi.io/fluxcd-source-controller

fluxcd source controller 1.7.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.7-debian-dev, 1.7-debian13-dev, 1.7-dev, 1.7.4-debian-dev, 1.7.4-debian13-dev, 1.7.4-dev

Index digest:

sha256:2303b0dfb0a3c39e881ac72f227c7570592f5db0d1e833275cd2ad6c5dd820cd

Manifest digest:

sha256:13df73340ad60ddb846dca43c9dc6c6513d5722cfb62eabba11062d24c5ecc83

Size

77.02 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/fluxcd-source-controller:1.7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/fluxcd-source-controller:1.7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/fluxcd-source-controller@sha256:71125a1e25fcec15a56160c3bf90149921b85c0574dc9474d7ff3fb1fa79d2d7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/fluxcd-source-controller@sha256:1757f8db5b78d13d8a0b0ce8192beaf271d4b03b6b182ac54329280a299c1a38
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/fluxcd-source-controller@sha256:550bbcbdf2a92c01053ce09724b21e1ffee7b90a659c49a6e284339cd58b424e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/fluxcd-source-controller@sha256:25774c2932531ed2e2f7e850ad85c7203e203ff4ee1f0fecaa3a30f24deb5bda
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/fluxcd-source-controller@sha256:5fed2c97b6ad52cd2e510e07ce412d53bf11e8d653a26b45ed0cf1d43dc90d6e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/fluxcd-source-controller@sha256:69d5f854433c573bbe4fa4a0c67d290f5497bb7a5725ea4c8a4eb71c5e7d2bfd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/fluxcd-source-controller@sha256:79910a1099b45298c4577374b5f73d7a435c014ff527ac7f75e897e5c0ec4621
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/fluxcd-source-controller@sha256:09e9e0ab449b04bdd8ebf7c631afdd0679c356ba79fcec3b41ec4d35a78b79a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/fluxcd-source-controller@sha256:7b64b4457bfcabc38ae9b1b1104bcbecd9265a531b445f99948194882eeaf983
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/fluxcd-source-controller@sha256:607fa51787abd25f386590888bc7a8c464eaf5d8df41ad8824b66111093810c6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/fluxcd-source-controller@sha256:8642974b6a83b91192df69e82f521d4e105b2b6ab2d648022f651f185eed649a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/fluxcd-source-controller@sha256:76793aaab32bc034a0d5050b8a62373d774c64d6e420d12c3ff471aa7f1e7d28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/fluxcd-source-controller@sha256:7a98322139d4fad9a9feecdcfd998664ef13f9d21237c291928cc164512a98c0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/fluxcd-source-controller@sha256:437c15f7f5ea38af3aa75172f70d0b0501b9aff7d151961d6cefa7d234d308cb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/fluxcd-source-controller@sha256:dbd05e0ea467a48a239388a2e2b7cb115f747242e82e1bff58f1720bf7216aba