Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.2-cli-fips, 29.8.2-debian-cli-fips, 29.8.2-debian13-cli-fips

Index digest:

sha256:7f7a411ce9411477a5341cd3c959f3a77b9108507de63e6fe57ce562e585b4e1

Manifest digest:

sha256:f5cf6c3ecbad9ac9db0a81d17fc78e0cda60b9b36774443e18c9c747aecddbab

Size

112.12 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:60628ddc559bbc1ca02291e40f18a9f25a9aee84d82baeebc954ad7072522a3b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:19889110034e08dacca987bef54e8012bedff46d5cc84a7c4c0b7761151c7411
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:b7f6d68443afba6a6f2566dd1e781349f9ae96599c7d0bf648f61498064b5516
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:dff36baefad9a83aafcd4a68787d1be9496218ae3add9a9f75a923268fc65495
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:0767b6fe07cdbf0fa30204c839b291f2399168dd42836139b4fc32addef73cee
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:06587490a34d8fb9e83f68116f35997234e8029ecc6798c57f705c5b7af4b35e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:84dd1820b8c32c2a883fee54ff1fb5d9921178ff94e7790693d0247a0e14b11b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:aab9a32ff9f753562b28f50f0ff4d3fc6ba8ff6aeb072f01622dc1ff01b1d72b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:e2f7e10c7144020ed84f1acc47454f0c8b8651433391432e57f532d7c2528e28
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:0305f55f9c216e469c96d6dc1db3bfd743370a8c83fd7cfad532af4184ac52db
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:bacb9a95b3f47bcd5ca1b0432c8a415859dc3c9b3914965e6fab00ee1e798139
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:2a569fb84478bc6fc54c72f6d0438b324774876f1b90609761af5dcdfaf85f6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:02f0ed2923afba237554128eea3e64b916dd943fa6e65fa718688314f879aa07
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:bec5ce6dae043b43dfb3df1450f1ee756165de8121028774bbcc0cdccfea4fe9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:0b0192481ef8f509097be6d45ca48636d77b5402e6ff37f7f3c98ee883a90032
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:a065efb30e6c1a0db4f02e9770cb1a273f9ab47285623f593e99704860ba76ea
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:3deaa9c1b129a411fae37b85830ba80d85045d0b505f9517d3091fb29bffea67