Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips, trixie-fips

Index digest:

sha256:344d3931a1d46cc44b7a57d8c6ea1c2327842ecb828a1cc157e7ca31aa928353

Manifest digest:

sha256:2f8e893b971e274d85f3f5ad8b6b4da510560d4dbb499d8c6faa7cc96eda98e0

Size

13.37 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:b6b6e7624b64dff1e4063a1b38753c48427bd6d69c75a07564c25b4cfeb470f0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:602b411f09c19928102609d072883b60ef8f0196a7f6a1714c061a6dd8f0466b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:222cf26192c4dbfc79928e407651bf44f79a97124c4a98df8edd4df67e327fca
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:75d90211d35baddc7cf752209a9845fd27aeee4254fd4b260feb3f65d6741350
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:2d22116f9fb8cb6c572c697dafb45448d89ee8de7b8ea866ff73e1278c851f6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:46136fc6c1335600ae3b2930d156fe741cd111936e42a8eaa836c7be4cda799a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:9f100e6abfec803a6841956cb0f879289d06b63b73353d4cf82db73ad41c0f17
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:7742fa785f3fde4b63d726455ead8b28cfdc890aedcdc1ab54e0861ad67ab8e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:a42830eb0a1c391407acdf0de4d8c9551540781f2bd37029cd1b971c0ab84d63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:2d2894cb7852643f6b1bbeb6a72d106c540a8b09d62e952d59e30a249aab5f55
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:8d233d87ddd12bb5cc5b02d2cae076c846ac0b565300b130fab5fd0d907f8b16
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:d91788f1abc6096a020934f0c22a0fc26b16f8efaa5a480bdf17495ef6bf834b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:735bb349a1aafaa96e658bb8f26fbf7da2699d14d62e6471a7d8e9c181c9e74b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:19c9c1af277a7336d3391cd60edeeb8ad7661675136f0cdee0a719881107e4d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:44719b0362e9da4fc2e7e0ae824d04e9661d705bd99e38af32ddf51e541b8283
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:482eaac496fb368cacedcc816e73bbc2f1e60b908f5ff4a0084908d34e5bf01b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:8be52097aa0e4f29f8ff4e02da4a1c8f893a0c3d07bc4abbeaef9ff35e823f44