Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli)

CIS
linux/amd64
debian 13
Tags:

29-cli, 29-debian-cli, 29-debian13-cli, 29.8-cli, 29.8-debian-cli, 29.8-debian13-cli, 29.8.2-cli, 29.8.2-debian-cli, 29.8.2-debian13-cli

Index digest:

sha256:3031bf86afdcecb57f28af90855b022cd28b9a9e5586f6706627dbf183565578

Manifest digest:

sha256:cafd1909ed0302f238116d9ea8cb95a3a6a246de198b3c0ee9327510921213fb

Size

111.56 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:7f6848d7b607c3137e5a47eb2038a361ac1c5c3e368a6a73befbe6de1bbd4f07
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:12aa816a7950eed33cab08f51130c4e23fc2aa3908350f1c88fc699b230eb0ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:5cc697b8d77e73b6b38e9457eab4dfd2162275ba56c7636ebef8e27a7118e715
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:0383247a2da4181cf43b9ba1188d1c5f201f39f0db03fc931b83425209741aef
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:d326aaa428b9da889cf4ce56baf25475ac6d63aa7fa0a2fbd14aa894206e1794
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:2992816301388c055fc668091d3c0859540e724da8885d2358c5201855dd88e3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:735e0b5fc038654cdff95bab52f6afbb6c449a81c253e8eff9d0b7b59c3b8c74
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:6b4537a70afaa62a4b0c0cc2f608e95c8c92b167024b470581beea6a65ddf0bf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:36a75ad94e57ebb3e257bd4e35a753779af61d7d354004211807c7cb15d2e380
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:4e3b4eb115848142dc419fa5b48bd396bda6e048177695dbad7196ad2dd08672
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:21c7f549143c01bac01cc53d34d25c15881fa3e184129a732b853f0336d1c7a4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:829994e51c7e29b0ec0902ff7dc6d2afb2297863ac75df4ccd7e770b6e7d216f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:63c960e23404acadde34daf03cca9f14f7e147c0167a110f89b7173416c68e19
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:74fb0655bb1dfa4bac92f25a426bc18bfbfd21f0df10c47bef9dfda2d61e342b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:2220bcf9cb6b955ad4105ce80a6ed8f1b450141e43171deb590b3a4fc0208ef3