Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, dev)

CIS
linux/amd64
debian 13
Tags:

29-cli-dev, 29-debian-cli-dev, 29-debian13-cli-dev, 29.8-cli-dev, 29.8-debian-cli-dev, 29.8-debian13-cli-dev, 29.8.1-cli-dev, 29.8.1-debian-cli-dev, 29.8.1-debian13-cli-dev

Index digest:

sha256:5df5d93d44bb1af8df78fa024d548ca64e8e815df0353c5c8f4102d13782871e

Manifest digest:

sha256:85738dea92ec1476d8ffe38aa708ad6a36629ad8f9bc5b9936cd1772ccd2fb4e

Size

178.39 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:46bd32568751dbfefe84d704c23fc01d522316a403662e687cd7fc877c3bf642
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:08f53bca27aee2c27e3cf11a046aed0c97f34a613d276faa7a15f874782ee88f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:116bdfbfdb621fbb475b42034a351c303dd54a26d085a193e754644ed5d9770d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:4c68c4bccc52abbf6b0d2c17f47e2cc1704da16f37e9061ab904efb14bec9880
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:d7592bcfb624d47af68e13a5cb3475d8c73d27c4a16709d112e7b746b2a5381f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:476a9df127bb8f5ecc5c42ae68f2b439e1b1837f6b8656c79193fd36cfb1a155
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:320d7f8420e6647921a0dba4a982fc49e409f940a64724d3366ddc49f5c15188
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:6da3917d663debcc43f72e3d5a95f0541ec90a4030cd44309b87ab5860989118
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:acf4cc8a77b4d9a6a5e582a22e6a1e5ad624715112232abea347712b0ec494e1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:7c61ab48b12eeaca41853d51fa8bdceb4000c9ea48233151d4717e52a74e6fb3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:65279ecc4975c397830dd6d02eed6b2ccac3a926a010dcc4d2776e7fc201f362
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:f35594717dbf57b7d364ef6cdeb6055c97093465d8f2f36680b2951c234d85af
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:126c02a6fcada2c3ad654a0ff94b369fc20dfa91cce372824adec9c2262a92b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:f44a46fd47844e2b71b1d20b7d8d63f03a3d3180c4fb9310ae30f3b0214de84a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:6b22acea45cdffa17f5c2d95262496ae9c6f9bb84f8573331fe5c0fd9a57e2a6