Sign inSign up
Dart

dhi.io/dart

Dart 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.5-debian-dev, 3.13.5-debian13-dev, 3.13.5-dev

Index digest:

sha256:ff6ffe9e93172643631a9376c42f27759a515e6d43bf8dcee1c257239ef8eae6

Manifest digest:

sha256:9c2e237aff3b8b8215b8e29afddfe824893ed8688f3c3b3a15059fe66107d30b

Size

217.09 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dart:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dart:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dart@sha256:6ed5abb5cdd2f9fbe73ba201140a81aad36b3acd172f31fbbdbf02cc23aa0a9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dart@sha256:7fce86040d449cf7a20ae44a29d3d20e0ccab05d66322df9a4570606897ddcfd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dart@sha256:2c2137909229d2625daecc6501bbd864cbe4817fe8238403dcb6b91c37c6a43f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dart@sha256:a6b3b64ce62dcb3e67cd6792c0b9f7ada82b857b609a7a630cb875d9c2ae5a3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dart@sha256:d71f62a8f9f8fca467d6a8dce88ba630c1083d69a3c279693db077ac861d33bc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dart@sha256:da5b956a0468227568e3de4c0bef46651083c04da7fa241efa0ed8ce820b4943
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dart@sha256:d3190e79e3ab950c28cad18ae750bfa3fb64a5dd18291e05ce56ef63f9756b4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dart@sha256:e830bc1f8d7d457afb9b14c4e9c5360ad0c22e0da04e146fd6c0a9081ee9e77d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dart@sha256:b3f59cc92c7ed0396f62ad3755210632949ce3f9fd3ab3a17fe81a1b147607c4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dart@sha256:de237d25f4d687e38e966c34339a20f848266e689b77de868a40863773d93662
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dart@sha256:16a53ce08ed6afc013a1b7d522c78f5488b4a7866dd82a71407c46ffb1c0cd1a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dart@sha256:69039ba201ba3a00223caf6e80b31c00ca61e6f31ebe5cf476a6bd5663890b27
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dart@sha256:dbc7eb9bcdefcc84395e6a63a383130698e48d99b0b208bb1011fa097eada96f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dart@sha256:2fe8c89f93888bb574cc1c397a5c108eeae108d6297cf7195e98ba61e535ac4a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dart@sha256:35008e6e01e20fca40a312a29b7207e4f5cbcf40500f84e8eb9fbf78bfcb9c92