Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.2-cli-fips, 29.8.2-debian-cli-fips, 29.8.2-debian13-cli-fips

Index digest:

sha256:81996af0cbbdffcc26552c6a22352a5c799059a1d5f047f916970e0523aa05c7

Manifest digest:

sha256:c10cd81991b2bbd214f6892dce60e655eee246bb16219485b3dc319773462cf2

Size

112.05 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:469386e3f4a139eaa23f1d69b3fa1a6792d76a0f54dbb35fd26f26a7818aec29
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:747db2f3952301f6050054f79f5a53f123fbdc9364f090c86e8c3ea8770bf853
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:a8a4b5c283994415c076d30fee5bc28d6b1df1f56a6b662c6f1f49fccb402b49
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:605fb0b6c26ee4206bed4fb5b5974b838102f116a0300faae2d77368d2c8112f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:a35d9a38b6f3ec49fbb92c6d40ab03ef897dab386591bda9740d540c965246ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:50896a422b720cfbabaaf5319f7845c8881bf42139da78ff6ed092f1e86894ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:b0175d4a298067be5f1812df7153da04a34210722f4d127851750e7993d84bc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:b1fffd09cd58b502048c2ec2b28a88075a27fd4a4f5e93d225135450de78edc4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:5bb88303c8e7eb07a55371fd998a851ca6e85cc2a1236f49a62a3715cfc18f88
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:b9ea90901d164d2a53aadb352b48a7e1362222f3d76cc7adb574745ecdd937f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:e527495249476abcb4265ed4a115cf116914095750afea31a7e4f3b086f8e3f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:2270522d85e43b84e0e18aaca6923be14e737f7ee02de572fff82aa84f4a92d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:5982b5f52feea70a2cb9397a9ea04f2a0f3611717234709731dfcb97d53b0313
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:09759353604e6cadd0fb08dc05f45cc6182b0b9ca31b023f9479292e95c1bb24
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:890e007d9800aadb2e6a264a963a7be7b9aa2e3b0858104d608aac5f242ad085
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:a255d8da7e48feb3bae6b3b66d3bcdb596a000628eed353440e756e8fb51496c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:c526af1c82e1449e6df565039fbae673af0414d4a39f4a3970214c32522f795c