Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.2-cli-fips, 29.8.2-debian-cli-fips, 29.8.2-debian13-cli-fips

Index digest:

sha256:260e6e0e2f5d541c8b9fd4a68b6a591dff9e3180d8eb5ec6dcd2b2ae92fd65ee

Manifest digest:

sha256:012e3ec00929772a0376990ea83dbb6915bd8aa87b90cf951384b3db945f0488

Size

112.14 MB

Last pushed

23 hours ago

Vulnerabilities

2
8
1
0
4

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:0243b7c0a0fe8b610a21d2945b5d98e0f3242699278ef57b0e400c44ffa11234
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:e997d418bd111734d1a24cd34758ed5d75969ebf70e5df829df3e4848a7f51f9
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:729d804d61768d91afc03e7557d86f544eb828170b116c91aeb894793228774f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:ceb5461f8c9c391a3b74e97ec0edef5aefcdbf5fd0d2f8a4af4da8bf9ed8ec8b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:81b5da8e7aaec3035c954fbd7c452266d12b859d1f955bdc0a26b525402925fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:1c86ec5849ac6616a401fcca132f787f9f179be9988979500265f3999b7129ad
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:37db64635f6e7543fdd74018cdf37c99039b29fa5c49503959b647bec6d76296
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:4a6847af85327b3c9c66a050818c2d36e75c9cc73488368d2e36fe2c642c71b3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:f2ca0e57071d502efa13a450fe44b6fcd2d3a5c7b1bd91260375be1636bea62f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:3058cb1d466c6ac16a4b26b3d7ca43b9a9c187d695c2556d526730587a396052
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:6c2c49b907d4fbdb48f3945fd83af8f2aa4bd70f83f8edc32b4ccf34f8a8e865
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:8b106119f8735cb78d148821a94e8feac8e8ee04e60c1b76d594f98b0dc89a63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:6a784351faee62059ddf0000a845855161cfdb04d59e4e69528f253e16005353
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:4362f737806b5562473f6b76be9d8db8c3a4548f37e0580c29c81690440b0df4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:362fefba370b804c67705988e0e138dfc1d27e3e44b890a6851ef9db0d88bde1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:6dd6d4406aeeaec304af20314e890057d30d77d8305a4dd9a8110b4209c7cad1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:c4aa2b14dda25213b12ae63e2b6b21c5dacfa62b863ffd12e8301e7a42394c03