Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:4ee34308de2c7a62947a6e6a8873a26bbab6638d164449be8be4b494f908dbcb

Manifest digest:

sha256:e5ef806d6480857f2b165243cb31005c20052cff580b2bdb828704c91d9f2ccd

Size

23.58 MB

Last pushed

1 day ago

Vulnerabilities

0
1
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:987d48abad585ad1dd527b8799f29bc631aa572784eb7edbbcfac4f839e8d869
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:bdab7156971f7b9ed8cb13f58158bc11eaee07d37cf8907959d1e334e113d880
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:20a21e034cf951b734f6435adff5951a84cfb4b8a2779b36fe9a8c4b7bd3f9ac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:addd95451fdf880650c5c84db4d9f14eca6740b5efd6798afa3a19b5dfe2501c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:712303014e211a73963fa4cde277026461ea3c4357d8fb2509c5a8d27e604bdd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:de8d7c63e2ccc110cc2391efe8cf80d950896d5cffdf9e517cc35cdab6ffc8e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:b73dc68b696f4f999f097de28ef7b5c40852e03880c6948285e345a0a832e028
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:4cb2f88ad35d967c9ef08e47da74afb2b291222f4e262c32086d7fd07acc8fc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:32f20db157ef993d498a462ad66911c45d58e3bfb2dfe69ab30791ea2fdf400c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:49065373724f24e790e62c5742b443ef6916e44d964c9c2427ec49f79e1dce31
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:0b5531809d285cb74127cad9d97641e22d8b11263f8820f8835961c840f955d3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:ccb5a5887293e1b198c8f97fa3c34548b69ee9f7c1c2d81e7f1acae74b5b2436
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:de1542ee072e160dbeb698ee55c9981253efa4d01e09d603247aa09cf84f7c0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:70fd1007b702cca0bb409e183a31891112b0b42612b67bbe4c9ed9b104b024d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:6a259998cc4c23a149e80828013e2c87ed225b9c72ab085897a1aa43780a3de0