Sign inSign up
Cosign

dhi.io/cosign

Cosign 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.1-debian-dev, 3.1-debian13-dev, 3.1-dev, 3.1.3-debian-dev, 3.1.3-debian13-dev, 3.1.3-dev

Index digest:

sha256:d6475e7ca26f990839df29ad013f76ff01c1342e822451e90b24b1cd5a0a16ec

Manifest digest:

sha256:29343a2b5e96a0fc3427f9907642ea1a6df0c2e263d9a0f7a139c5b1c4ce6423

Size

73.96 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:80e7c15d50b273c907bb8ad4be30af40ec5490b776e0af3fa2f3b09c9cf81159
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:f856a3db5d373636b9604c23a984d6819fc7f5f8d95e765c336965f870fe0f32
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:b4c00df758e0bf7d0e77d1419e81d83bcd2b30cd630aa798a28a7d5efdd5f00d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:70a6b5221e8b22c05111a87f5b2cce7409834fd089e1fc16cb8f7d7e69960e98
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:2c591503cad6df29539832b648e640cfd28bea48a93e0004f23e4ca675d5b8d0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:906d6fc177e779abb8f886152bb758abdc4c2edc684f97e4b77023fe38601a4b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:ee93377136bb44283c9bb2de40141157a3574346c8bc393bd675b19286cf0f50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:2fd1d817c617ba71deb8a55a05edc6401976ad6ef6f2e74b8c1521b50f26989d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:59496746b45243d0d4a75d3c49c26e2af943abc7b1002078f72252e0afe0cc52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:e92a58ebbff09e529c88e5e1511bfaaec7261f6a37d6a7844e84471349f91aaa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:929bcad35c1a596cdaf61ea84f7ec3c565afa6c432acdf850881029fb3f5dcd9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:1230c614f7a58d185c08a3024cefedd17059e314c669ba7b6e3d0cb69f0e84e6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:1d7b89c8b4a30f321e0ef0b38bedb6c6d09ad6582c2662d5cc19179110dddc5e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:197d4633b08f07120ed5cc378a3c3f79feba2789bbc5321b912ed2046ef73e9d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:2bc9ed747c438fb58a11f871180313f13a2367a20bdf0a7467e014feff778324