Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:c6fc0de84b65bc20346cee5f071fd976ccf383431515db2a4d9721ca936feb9f

Manifest digest:

sha256:3d0406e9b328e382eb0c34b000f598d60b0d431908940a3118943fd8638f9cf2

Size

23.58 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:6666ec492f6d09756d2dd3847602a426b5bdf81c971600f67846cfb45239ab91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:ced77d012d0524cc83e566bb000d92e8fc32979e47dd0d12790582a27d8468af
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:894fefb95737de6eb86201af07518df6c20a0580b0fb9e28cf835f1ecac60817
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:8e45677071f2d548be3511f1dc3864c7460da4be52d29fd34b38425749025675
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:36e6d7a82a0b334fe9352fa764670ac5d78ef7327c1a2e94eda9e8f9372df739
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:245aff870c6e7edb1feaab8d8e1453d566bf5151d73739f9c9209d66146bd694
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:6fd9cf98ec68f27b3a3a65d99a9134cf52a18442b1619e225f54f014ce7349a9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:7a5a7a416578c432cf5ddda530a5c2e9d49af46b54d44e2e6b16c6b82882e73c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:7ef7a900fd9ec7906af52a16e1405d6dfb5fde6c427a80facb6ccdeb83d748f9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:3fe56708d20f4964700a29af06b70d18e333636a40d5309b0d6b99a716060b19
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:644d7e937d19c0fc536fce76819be7c386734a531c41d6f8171e778e5468f71a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:07941b13a27154ee8063f4cb66627a579c1e39ad65551d50ea9f90e853a550fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:3145e4fd7523e29c98c6ad417a111ff217711c16d3fc2da8bf3811e3c3e00a2c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:dea08799850595e5d05fea274f012a7f403aaa0ea0c8161b84e637c2cd258ad8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:086ebfaa85a245917edf14d68ff892d621a8eb72b4408123af68986ba1ddd3b2