Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips-dev, 29-debian-cli-fips-dev, 29-debian13-cli-fips-dev, 29.8-cli-fips-dev, 29.8-debian-cli-fips-dev, 29.8-debian13-cli-fips-dev, 29.8.2-cli-fips-dev, 29.8.2-debian-cli-fips-dev, 29.8.2-debian13-cli-fips-dev

Index digest:

sha256:770b44e88fa00d2e139e290350479726f0fec5ac124f96c3265d1376a44dafd5

Manifest digest:

sha256:aee627d32eb4d71d971a482aeeeb53664bb577985bd1fc026ee0046356c50e57

Size

178.84 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:b6c522727fc6cc95256956692db4d1362d1d5f856138cb59385f95db34e53b1d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:fb19914c6312cff5561e7706564e1f505b9bcdb1f18cbcf2176cb5f4f155d429
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:67faa4d123e53e091607ea441e04717de2d6b9ff5cc4084f459554b109a4c9ea
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:d5c46c7d6863a1398a0fc87079789516c9d028d4d6db10a7d2cb36e49fd7c863
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:c00d4c78f2c42280708fad4d6b73b7b35cf8b74b525f16ea0d1d69c740310410
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:11e65cb1e0bd2742a844869596e26e2e023c26cd91018228436f2375bebf9a32
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:2dfe80387dfec84a1fba032a258c6c26d72f47402bf480570f272b6166dc5013
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:82414a23272ba31f8922620ebae810ef3d5c2f3844fbed70011756f484658bd7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:d4c3ca7eb5326dd1f5ef12042976ca1e160e5f7333015e8157a9971534de2941
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:c12ff11a8667f09797c115bda0a5811dd35e2e98e1b5b7185b2c79667e315309
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:9fc7e5331badd13104558208219186244a34f37dc910e62506a2f09868e081a6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:73d7e56ba459f7872917aac88db3eb23271b57abc9366f50ecba1a7b831036af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:be2302531b47e664f31151651d921d4dbabf704230b2da58e7db21e11faf92ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:c9ea0c0f6dcfc9c7e0c1517b71a97aea6b491d095141ce32c2bbda9351f68136
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:4beba94c12654218becda0cf4fad0faf33cf4989fc3fcebf33c8d868c73c8132
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:3b360559d11ec53ae5b851c4c4213d218a50260a7182d4cdd4da15711870fdbe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:366dba5e4e191988928f0a34200028b74f9d64f1b94a43bdb88f213536754c38