Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:eee6210baf75263c37cafbc89662ad681351b90035008c163c2f664618bb8fc7

Manifest digest:

sha256:2bf5dcf86f0fc117e01af4321a1b9aae455b4eaa565576940a71c3eeeb2d0d48

Size

24.33 MB

Last pushed

1 hour ago

Vulnerabilities

0
1
2
10
1

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:6d9f424a4e45cbc00a9e1972c45c90c03e01a0e70244856166a20bf22d46adde
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:fd5172e7da5a62c1cf6342791e8c6d29d129aa706cf7c16d46fb1f108e0d6388
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:3f8db7e7a6466a6668a149022399f9a72a04c382689ecdc62a8a5103c7e14c6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:6739e969298062e537672e8cbeb2991c7a74cd31297f223cbf69691b6dd2079b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:92eb66b4d56e077db135f7d6ccbdb0ba51aee1b40157e04ac1e371d8324b7b02
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:292303bde11ece68eb67f0dcfd91e77717b053c0b34ea092b6d13113db60fa47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:dfc315556b137c0d28526a82d019c72647a0f8c1d9c26623b69b4b06a723e9bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:f08895d293032479030aa43972f02fa8f419b005038abe9682216775843a949e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:2f25de41888e36c92cf7b6cf756b98a607dd5d18cc040e677e0913f74a70e90f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:286aa2463015afbd68572c335f9debb2e70fc3843420e648b65e916e8d317062
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:c214e681c8cc9225c0437dfc3b65c09f3ef38e39b49463c8e9b5f406dca39085
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:a8468c02575fe3c5653edd8e220d948771fc888487a2b99dce7fe89773d6139a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:199d19b5d244601a943f8757951af6020880abfa3eebcc37a8c1f562012bf6ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:72d761360a6e8b7d76a87851305a772e946c43698c4df557a56fa7439a806a9b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:239adde2ead0b35dc10533bedee78338a6b0101c9255f01df0504b73c4fff5a2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:65392daacfc225767d7baea135681082cbe60a07b502d042a8eb7d8f1990a968
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:e006678993da12dbd08bd8841f7ebb70a616c2ef23e9c52d6a6cd5f6d75ecc98