Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips-dev, 29-debian-cli-fips-dev, 29-debian13-cli-fips-dev, 29.8-cli-fips-dev, 29.8-debian-cli-fips-dev, 29.8-debian13-cli-fips-dev, 29.8.1-cli-fips-dev, 29.8.1-debian-cli-fips-dev, 29.8.1-debian13-cli-fips-dev

Index digest:

sha256:101bdf7df3acab2e82e2092f71d1f37368818e78f98e75d1374e2f8eb41c7ca6

Manifest digest:

sha256:042b1cc0ea0cb67c7947467bf08ed97b68963821ed9f355dd314ba70ae545ae8

Size

179.16 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:d3a33c393ea5be59a90d1a92752c00becf41a9285cd57e146488a8d3148edd66
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:43974adaac29251afdb158de21e289353dfd3798ec43de084557b7b1d138f1dc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:844027cc467b34cfa33c9b23ab2187a0b31d5260e36e81e24eac130563f3c568
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:76ee0446a281b3ac774fb6775d428d885cf9b67bc0fca5bc30bfa9a73735545b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:84e459dfdd3f8cc06903cafb8744b79dbb1d84236f1498be3c92390f069230e9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:ec5052730ef9e5b9a6b1de9322c1eadf77648bb57768c765749c77a1b5a6e518
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:722d16afc3748e33e911cc06843942be04641f6d63c2558251ccd02b6e984ece
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:d28a368870602c5d7e89dc6702cab960fafc1fda1416b0d0b03b3f983f7ad7ed
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:d15cc18f1c2cd556400ed90dc7296bb3f4c1c9f3f11ae72b9064e4f1e2617490
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:868b2ae1220c2a827a67a12ac6f1e78a07d943de62f96b96f20b6bd8aa1fef5e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:f2faa56d381faa3bb44300a8f2ce4514b9c3aeb5da7ffd198d47afeb30fc8d53
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:845a2e1999453bec74c09be91cc77d26e1f3222e397a57c62ffe14660ef3736a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:b38c01d272ca676f2d613cc936c69b0ce725b96338d60457c729b2889b009d0d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:d26ed261d6b7e8e0aa5b2448db6f1c0be76032ee6a374974e90611c5106944b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:f7f7ee1b90e48097dd03d603900a34887d7472bec71f0a23aa0322db2834832e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:31bd55572112fa6ac89c69ce0cf10ccec19e8daa52801941b1b1199a92605cb4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:d898e1778e875a6d2726358e89951480634b3d2ad39255847d5911ae64546689