Sign inSign up
Dart

dhi.io/dart

Dart 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.5-debian-dev, 3.13.5-debian13-dev, 3.13.5-dev

Index digest:

sha256:c4b7c8bf318257dbdd0f90ae94e23e6368561ea90bd86e9fa3b1454d58c3aa4f

Manifest digest:

sha256:a9eef9f20a18f0e013726b5b10b15bff8261217bee2c2465f09d475bf694eb98

Size

217.09 MB

Last pushed

21 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dart:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dart:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dart@sha256:f945e0308a6a5d6207117b2e03ca7c718a747f34d27aa57c68996dbc77a209bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dart@sha256:667eb380c91803f36236599aa3c2630246874f4484473de72028e7de0cc196bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dart@sha256:277dd2a37382125f5abc0bba930078de9371e39caac7acd691c6f9a5546cb2e4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dart@sha256:25ea319f7879122c0f7cf856f9121aad60180d817c5696e0d86e8d17946f4883
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dart@sha256:355ff06af5efc88f6ac9a8a017ca816eff286b21a8a96d64d3391318662f26e7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dart@sha256:7e5851cb4654cdafca92ef7f5ccdfac28cfb9b6440ffd02a4546e834e45b0e37
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dart@sha256:0e87769adda4808ffd008491a7814d240e340e4efd25cc4cf299a3638a590d87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dart@sha256:01285c1377e8e1dc342bc0db27f4490c3fb1aed4769d3495df476617c3d63274
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dart@sha256:53e9fe24401ad16230ca48ad533b0abebe78d772740a5c92e18f5c5369f22e2d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dart@sha256:2a124367cdd553c5abf2e263ddc53ef7574a7c5630d10aa5f982e1d772804583
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dart@sha256:8ed20dcdc252d2841c19e352f0060bad25ac2a8de5512d2c0b189ee927fb59aa
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dart@sha256:c9f49c6cc325884ed04d9d54867986a45c50dc6e1e49819e3399291d384c3d99
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dart@sha256:7b4135cb0bedb3ca0cf9bc26e74688928064aff3d647f2f7f8c1bdb9ea5f5888
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dart@sha256:dff7c8354c04e29cb0116569f0d8bd061e6dab8cf41e7fe5b7afc53b0e3fb12b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dart@sha256:319cd56218eb0598aecacea7cc1ade35dc583d54a9be6c7cc3e80f982f402709