Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.2-cli-fips, 29.8.2-debian-cli-fips, 29.8.2-debian13-cli-fips

Index digest:

sha256:1a7ebda97c5e1f8e301e3d7264eda4e1d593cc47d330bf85f3882be2c415eae9

Manifest digest:

sha256:b5b56f2caf5f9c6480ac0ca56a4be7f2fb3c22cc58434008f47fff24a1052372

Size

112.00 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:60a0c5ea7ba1b8af5add46149181bca91977fe23a0a54d2e9f3294aac6711e20
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:87d1cb9ccade1a2c7fe9528a1af6a2e594d2c6ef5fc555d47cc5d744084f485d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:7ac1931cced4ad5d37f229392abefa865a82eab4d0d980d9e9e140af20117545
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:493ece6835b15460554a4d5345c89cadb35197e0d4afcb459bd0f37d4681c8b2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:91c2a83e8fb991dbfc3e84b7de09753517c95c6fb9c701f4a8cf6b18300cfce8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:4ce583751ec49d664f371c4147e46c26cd8cb60020521a98059d5801fdb8bc67
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:3e5518fcb607ddd5fd27ae17821b2aacaa920dd03d2ede1ded03606353d10472
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:b3f86d1a107765044b395cde7f597ab979803225f92ebdc6d978e77367faf2a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:31ac72dc38519aaac0acd409152dc11e8a82bff1590c441ffc57c0c91b3e3327
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:be0184a9e298def241e660dcb91735525ffd44f86b94ea572c6eb0c747f3b186
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:a5f76725a5c5d75e1549410e75bda31d6409da5ca134dbdd9cc32d3860dc5124
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:15d4dd7ef098c0539c7cdfe556c2d2ddb0b87b9c7ada25ade681b5f7d3b5f90e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:dd52575f4f032974c4643563c78ec9723bc64bb31e6df19cb6ec9a9fa5b0336f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:ee024d5e4e9d7b4a9f8966bee27b287dcb78cc72f658824826af1c9d1a5df526
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:36ee9320bddfda0322f3a98da5838cfe89e10ae79c2323ca6a411436dbadd923
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:8621ccd68ae8ba48b8bf27038fd9b4544f9982d635a9cda19d32b8330d8d7725
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:a0d1be70b8235698ff18cb56f8b639314395e0c747ac27aee439fb5efb8e3a34