Sign inSign up
Dart

dhi.io/dart

Dart 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.5-debian-dev, 3.13.5-debian13-dev, 3.13.5-dev

Index digest:

sha256:53ef864d397faf896df6dd13959edef44a19524ffbe378dc268e2ae424776159

Manifest digest:

sha256:e08907bf1e214e75b8fac8b565e84536633dbf5e487ee66695d79130edb03009

Size

217.08 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dart:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dart:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dart@sha256:6c23ca60f2f75315052caff66f35d99721ae5e9c81dc864d7f6e0178fd5619d9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dart@sha256:feac2de36c81060dad1ffa95cbeede973e878d7293863578690db0da73c1e895
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dart@sha256:109244d7f216cff3159a6758db2539b972c57e0c1eade6c0ba26ef9521415370
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dart@sha256:99ba0b70fbe246e5aee44af072ce6d9c9c3c56202a0b5ef348eb1d9cec2acec3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dart@sha256:b1c362b9248eb61822c4bde445e618e8868d8f38426570dbe669227fb0917990
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dart@sha256:d45dd49723d1c1bd9754e83af7719b2e7999761c099e697f0fb060965542c539
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dart@sha256:622d51b61ae5a2aa2c4b3eaa0c6e10b6e9f8292971642fa06aeef59fe65864bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dart@sha256:b737b3d2ff6b4f7bd41e6dca23fdbce65f315c30698cd4d70cdde7ba6970a7ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dart@sha256:e5feebd6435b95370b93bcea957c71be0e5d5749aa2e5d9096b8a26592a99ad2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dart@sha256:20863054978ff81c9e86d38674eaa32af1c4c627d0974348c9de854f3b46c288
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dart@sha256:f60d5d135785a6144ce5c2533b42a7b9a6c6d64dfd9d07d81694f65eca69d82c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dart@sha256:eeba8e4c3230dcfcf1a57a0bf2eb834f7f1dac736a0b28e685916f1426bdba28
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dart@sha256:044aeb47a45ec728ab370396ad5b7966711df241d6f9f8711697a59258cbcd55
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dart@sha256:02429354c28f601f4f647c9440650e9e5f23a42dff5554453a4452aa6dc433e9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dart@sha256:76e9eac05f27a97b3b42fc9b55cf90864445b0ab755b6d6302f23f39f3047d3c