Sign inSign up
Distribution Registry

dhi.io/distribution-registry

Distribution Registry 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.1-debian-dev, 3.1-debian13-dev, 3.1-dev, 3.1.2-debian-dev, 3.1.2-debian13-dev, 3.1.2-dev

Index digest:

sha256:914c8f61c3e74e9655680688f3dab56f68f2e422e8db5234cbf5c55447013680

Manifest digest:

sha256:dd516dd65653349661990ec3fc909d050bfe8d81dbe18ca5ce1f8503783a1eeb

Size

50.52 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/distribution-registry:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/distribution-registry:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/distribution-registry@sha256:c24da19b18fee5d1844712a90e857ceedd123bb7b464ef057ccf0c6c8441b462
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/distribution-registry@sha256:2533c9d458871b848e1b3e2084972fccaf45442ba2bc48514718d2faa671db2d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/distribution-registry@sha256:35acd2396a6ba842f63ab72c1d0a5887e3de752fbc67406c70a519bdac5bf33b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/distribution-registry@sha256:c658882a9b90c5b06e2c8e8e7d06ca128f75c4c011f5e80075738dd193d1a38e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/distribution-registry@sha256:5a02e3ef439e955eb25a8dff876714b4db2ba24bb923bee450c7b98049192830
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/distribution-registry@sha256:90198e353bf80714193f17b5d1dd1dc267f07ff4eca5adccbbd1c678c14a9b48
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/distribution-registry@sha256:c41e5b833a001511e7add612c67d217636e937db7fbaa8ba8f5766225b778081
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/distribution-registry@sha256:ee603a11ce835fa4270103f0859c62f5495d2988926de2ccaca8fb5b044b888f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/distribution-registry@sha256:c64babe31370590041cce03627d443edbb449f06bf37c219ef6f9e1558256dd5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/distribution-registry@sha256:3ab1119609098639e05972c85edb274db67eafb368d99b6b6f9e0fa2e658efea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/distribution-registry@sha256:5d08a8fc46b42977e8bca5dd0164307a2e68ffe75e30221cc22da9bef570b976
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/distribution-registry@sha256:9ee807207d644aacd653d963d0e0d9682593a45671791d68da9c35307a514036
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/distribution-registry@sha256:0b0e50a8f2f8cc7794191075cd81cbc07d336c1b5a070e82350e28b36033fcfa
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/distribution-registry@sha256:fae9985c33d71a0ad18c3ca8960291b8c507e8291d65eee2ee5f41f97eefabe0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/distribution-registry@sha256:c2586cfa324b227158ff2ffb9e35ba9c99def07a01fd6a0d197d82512ade24a2