Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:61dc022a1908439c478ed4b00e883fe8a7a03540fac23a8aed61352e28e6ae07

Manifest digest:

sha256:b9aec4e96f5b945ff8120cf4618abee42216d194329b5c82b25b32bec0feb674

Size

23.58 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:4f591f412648b257c5f97da81d72391cff3e940b5a0f55ede588b00a24af3384
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:812f5b8815cbc5bf9684be5e4f9fed2dc3d8ede05a2fbd048909e8f1ce61f510
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:b44d31f8f71a6aa197d642891b2f1cf60a7bdefe1c55f5d43f23c7111b87711e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:067f0dad3a14c99b04638bb2c07d55637e2c3c26a3af6f6d68adb77b1aaa5d50
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:8e40b9e1ae715cbca879d6f9f2a9c8f795b937cc77f61805040aeb0dc2eea1c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:c530e58adeaa173417a631fbf19e3a40b8e89d90c5975bca8c4396101a22f853
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:9690869b3902aa48d9d9b3d78d783eff10945cfc6289e0d9f0032c0744d72337
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:5710eafefcd6f2e479828825d83e26a9693ae416c52a95670583665e762a8619
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:124c919b8ca3cdc85676bac7a65fb870642cc9ec9d2f62f437bb85281d2524db
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:eef323c23b809fd7aeffb0c67929f1d6ec5730c1a649ff059ea847d3ffcf69db
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:ef44d33b615c4ed1323d2214066d157df3d985feacf399e528b6a79dbf5d6dfb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:b08dd91af019b9e55e2fef3891a4eba2a4d579bce89e98116d14469afeca3320
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:0bd8598591b0aa8b0db7cd0a98780ba8b35d66bafe071e568070de82aa8f088a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:5394c570ca6a867d0b43025b9a29f8099163f86e3ed1a6b85d55f31ed223ef3c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:9f28124fe8af25851cd893839cd9a404f45acbea72e23c8da06a4fa6773ff71d