Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:34b771176d6159a864c0ce5505eb4d68fc8ae3fd275dea8cf23221a477c7e7de

Manifest digest:

sha256:21db0071f5a79e95f245d5a85be3a0dbf626cf91a8244a44c26508b26d63b46d

Size

24.34 MB

Last pushed

4 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:0e1ba7f5c0ee4a21b17ff5323c8a77caf37e5b60828c00baac40190d6957f3c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:55026624281859d9fc9cd5e39028f07d1da049de67d5c9575d2ddf559f72e7a2
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:1912932a4310c26207fae36a85aaa67bbf1848faba1a34df896768c3520c6bdf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:551a5ee7a15999742c5fe2a5f803d5ac0227212dfd8dd36a74fe630f5282ce97
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:3eb0e3e4437371384cd6995fac1eb5c0e2f5e2fd0a3071ac041000e73c21392f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:c9f50102227c3c360d85c83a63dea0e8e08e368ec70918e0f853bd4a73f12c92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:3ef274c46ecf34e6fad1b729c54a0e75bbc268a7ae2b3a155537a4c7b2019995
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:de384012fdbd2edabeb73b76c8e8792bab13adffb86e1f053512ed58ae2c60ba
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:047f460bb36a7c4a05355dec5f354bf4d16224d835e5397968feae0aabc5d96a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:dc5f2cf20252cecc83953f5f127c51fa04cc2e88062622aa41fc67a5948e8a34
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:4dccf62f962d95f4cb10113f1fc840a33c0cdb83bcb13f8d663fa4da9922c179
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:00ab935af9487647af668ba37db2971c98fd8d5baf1e162188a6c54c02bc426a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:dd96aef8d0d0b9ae9f649d97bf8a7ddb4f2d6b1c6ec2f6467b480ed3d8713087
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:4c3331b945bb68734e6dbdf47760be29e0d295d4ff21520a9d5e58f4f7a9c77a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:797953d0932b91f5ec17dafd19537827ef757b34cdb129b0e3031691c294f884
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:18102c3bcc764d14cb6cd7145b8a5790d4eb72e003dee8d6abc3e416ab88e28e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:3da8c0c8bdf9571153c00029163b2c61e287b9be76554d7c3f696f521cb9f19b