Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli)

CIS
linux/amd64
debian 13
Tags:

29-cli, 29-debian-cli, 29-debian13-cli, 29.8-cli, 29.8-debian-cli, 29.8-debian13-cli, 29.8.1-cli, 29.8.1-debian-cli, 29.8.1-debian13-cli

Index digest:

sha256:f560ae3e457dfda4d2c5a20f26ffe80cf2ccc2f6517d14da0fbf6f4bbeb12655

Manifest digest:

sha256:80a5e6f02b38c05c70de6e9b254881d3e168b32a4f6d431ab204dbb0757196cf

Size

111.44 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:859a45dea7809e85dc3171b08b05b7b05ab9ae7ac61f301f1eed6f26d1354f06
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:bde1d0ce09793cde1bd8daddd0c3e9f0e0950660bf48653993200c8e02ab2c59
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:e880a0200e48e11b9774e6386cdb4172259223a0065fa08b9d2c46c94749f4ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:bcde642633dfdb2b36f472bb34573996aca1f087a01915a6e0902cdfa1142269
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:5524160394c22dbb42d978ef1465f686897372ef7b40c3f9049805d4b601ac18
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:eabd74023271ffb73d94d24d021de69d29033e52cfcc46e5674a516eea6823b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:07dca2ed9a5415f77f29b02082a6cd3b5f585c7317d31bc95c43498d56d7f900
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:34a2479618d0a33032ba97331953e373b494ecd69b1fd0094c151826c873020f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:904b6a7b9563a8113d521a449f3a9822f60254c71fea353bcbc0d4e3fb8f0aaa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:7f1f0ec72529e817a5d402ff37c402affcd71887017c33a44536f9aca0ae223b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:f779d17631737f20f71f2aa43b9bad3e99e339a3f0cce38aec18c0f058901e3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:beae7e2443e6b741c8c9cc8f8ce129232f8e52811261b71fc555cf0f782d2239
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:eb25ccdcdccbf7210e813ee8049fb4b159f0556a6c6f7792643b725ea1f29dae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:081e51cc95c7bced4009a7014601998d73de426bd9d6c01ae9eade1c324197a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:12ef128e5094a34a55bbc1a0455f93802f451f72e6d746c2749af6ab92a864f2