Sign inSign up
Homepage

dhi.io/homepage

Homepage 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.13-debian-dev, 1.13-debian13-dev, 1.13-dev, 1.13.2-debian-dev, 1.13.2-debian13-dev, 1.13.2-dev

Index digest:

sha256:c1364e1d38b7523dd9b7e6757bb5e7cb20590e2734ec43a007947ef4005f5bb7

Manifest digest:

sha256:ef7dbedc1f4a23cecaaded20d36feccfcfc51710958e2be65defdcce71551594

Size

70.50 MB

Last pushed

4 hours ago

Vulnerabilities

1
5
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/homepage:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/homepage:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/homepage@sha256:cdfb4bf3ba36f95bd15220bd8796a316a2a2cb77b2549cb0662e5b3362faf3f8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/homepage@sha256:fcbca4760f051941ba8a3d140d34b84e5065a2dd8d81b0fae2c94f804d876758
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/homepage@sha256:b1115b464ace1710cd44135602bfcd43fb96e0bceae2ca7dd63145c249e23264
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/homepage@sha256:6074eb97090fbca882cbb4fb34cf5dad8a474f3b93e62a02fcfbfea5116010da
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/homepage@sha256:6e5cf0e3a0c4d926d04ac77c58c6c01b041cf25ff5a505ab1383c9a0eee63122
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/homepage@sha256:0fae61f3ace51286c3f2391e20bfbcfc258b2a1ada1ffd3df14c459a87bd8269
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/homepage@sha256:651a557798f9117fd6845d241d032acc7c867d836405107028b35485f96ee41d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/homepage@sha256:77344472e353e06491eac4d7a94ffddd97cf00b1966dbd33568450f7d226e293
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/homepage@sha256:e5c765898df5fc7bca30c3e24dbc18dfd715dd5510cb6b63fe5c3cc38da847d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/homepage@sha256:7921ee23a23e503e408199e76b57097b7ba05dc595dc2fc061fb9c09167831bc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/homepage@sha256:ad3fe472d59b06258751feff0b73ca383dd0c45c0ee67e825d95f56073bbd175
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/homepage@sha256:b785cb331e8750044cb397db86eb6f72d0da5d674c85957dccbe54e0a28ffec4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/homepage@sha256:0d75c82b9370002fb523dc519707b15647490a2c842f399f6a185b99c89faf37
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/homepage@sha256:acaf3630e127df5c3d31c466b86a167346638779ee751ba91740b4b0d6ca29de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/homepage@sha256:54833592cff2e433840b947ac56e7bbae2246492ba00740938c8b6b503ffbd82