Sign inSign up
Nessie

dhi.io/nessie

Nessie 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.109-debian-dev, 0.109-debian13-dev, 0.109-dev, 0.109.0-debian-dev, 0.109.0-debian13-dev, 0.109.0-dev

Index digest:

sha256:ca87096541e12b173f2802e31b0450a96639d2f3a2074bbe1352a1f700435157

Manifest digest:

sha256:ca230ceec11b74b529e5bcbf397d62c6efb6ee4f5756a1c64dd086152a29cec7

Size

295.19 MB

Last pushed

12 hours ago

Vulnerabilities

0
4
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nessie:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nessie:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nessie@sha256:7cb8724bfca606320884144ca3964f06fd284de5af959a6f9e51fd77e1d6ebf0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nessie@sha256:dc019bb8c8853433c229b91c5ba7bb3fae903f3767cfdbaa716666eeb74e8d9d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nessie@sha256:13c55b7b5c95db6fae9cad75380dba5902e943dca0cc22e6d2a2de912b080885
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nessie@sha256:91594f6f141f53bfce865445f220cc7e122e2d9a736fc5fad4c7dea6f9880a6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nessie@sha256:2c8e2916027de1ba80a938d0a8f9604e690e2a810453a7d14e0a7d6879bc0711
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nessie@sha256:8d551f31cfe99101a05bc641fa9c3189e98466c7c34dc3e24a55de39da3344b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nessie@sha256:fdb47af741264305a184b6e8f2756d74e1ffabd63d308e0f2fd418fa2738c628
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nessie@sha256:0e35b161055fbd63ef4be5d35ff8d4882e22cb147c20e120a0584d8a1ee90358
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nessie@sha256:fd29e3d2835ca3fc29895cbc4f0300868501ad7ae9cf425e35aaf0e31d27473d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nessie@sha256:83913d4130bf53d7d9fad80adbf9e4be55a673df007fd9165ab4abbe4f93d08d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nessie@sha256:77560579f5475b5b0cced4dae3370c8c2ba4eb983f191cbca9cb546939fb76b9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nessie@sha256:2bcee293cb133cbd76b38808bd4c5b5312c979541ba13b169078977b9c3b360f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nessie@sha256:0f74d5929de1b19ed0975664f23e8b2cfc8770574addb2c7b6be8a0369256203
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nessie@sha256:e1c992b617d6019eaa15b5e78e9de8e3d19d5ebdb759ba59c9577b66cb2c0d2f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nessie@sha256:8bdc8f13b253bcbb1d4e2f145c215020f1cc23af5fa9f7f57f2224c672349766