Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:d361661706857e041f642c291f47729dce7a857c6679b2410c5971c3803a6146

Manifest digest:

sha256:7583f955897e38576cd8ba40de846e8910e70df5151a8ffd1ed98af9033e7353

Size

24.33 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:83e6dd18058d00264965ac1658245dafa861e960cc91ef14b83a92d92eb12669
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:d7cc6886700113646f32e9901397e36d204b11a39c1a6314dbc224e5f3a7ad5f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:60b14b0e59654c7a64674766faa9528a80157ee25f6742baba79caa2e79efb7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:20a327c210861780b6019258ecfe1f671114d8bba0b8b80d03522220e8405cd5
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:a1dd4440907c73c42b3b77f7a9af4a2d56f606c8d6ec2b5e51372151a07156b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:6ce481a44b4becebbabac45f2d94f9752472ce607e8e15dc5ff8616145b6c023
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:cb8ece9adb5f87695dc2f3f4767cb18d5e05e884d95139266aa18ff5e7ecc6da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:530a8b8bc4c2d070eb92c5f9be0acd1ab0107f1262d9bb90cf78bbf49dd40005
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:cb9fed88cbba039d111b067b19ad2943cc9c081a4d905742487b30fae8a65ffd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:b30ec08f18f6aae42c5def6bbd004714c3a92cbba1958f3293e4dba2bd6710ce
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:d09c33fe5aa63ebd54edbb60161e7bff2cc628066d78f8112389ad9ca0318608
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:a1b93a1fdaf01f38c38918e85e2cc9ada8f61993b7e730cf4c6d10cbcb1a2244
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:681f468a31b0e1dfda9a14c575c6092900131e9b3a055e74b83230b6cf7a8222
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:c9128897c7e5614b515b7041582ff5f4cbbaf10ec4afdc14f87650111ab19f87
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:f2306c4ff5f90016bdc18d017a7003b365ff7ac90059fbdfe129745d6bc4eb70
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:d149458f8a5130c046c45b2b7df6b428cb6faadc2427f34372f8d5d069cebd3a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:789625e16bd2da4d31fbd0384a611d2f0c04c159027c864462eca5ba967a3c53