Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.3-debian-fips-dev, 1.3-debian13-fips-dev, 1.3-fips-dev, 1.3.2-debian-fips-dev, 1.3.2-debian13-fips-dev, 1.3.2-fips-dev

Index digest:

sha256:8a1fa6cd99ac71e3a519365261696117dfee713b25a9812d500b6094ca6ceb0d

Manifest digest:

sha256:3ae300acab4e4e26ecea99af4a9340012cb5d84c24145530e849abcf142059e8

Size

30.49 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:5502bf5f9c26b89154f7dbcb115b474b7ff9ff0ab418a33ef9e85c40b4bc611c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:e8215b66fa7666dded269c9d831e813145eb7feebd2bfe4f010f8cb07451533f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:cd6ec074aeea636bbe31e02f98cffd0b9936cd033aaceab5ce3865ab195fe927
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:5fdc01a4c5aee81381e719a11d5e2503144e27cd0b07b39aa48c45898337d1fa
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:18650d220aa00ecef456c490c1aada62b5d5f451be5d8ffb826367606d20696c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:ad40f0cafe5f58392dbf26eaaad3964f3f1a3c639b71813f28fd31fd53583ee7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:9d910c92db428a3596d35e8cd398f8b9ed2fc976734bbc55ba51bb8f291b7522
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:53fd640a30cb86125489da7cd6887fa91a93d97a4c4d31998c9e0bafd1ef4250
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:382f1101fc1dfc82877f465d2ea6cb8835f0743bc92c284a7a2383c966d4c8ad
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:df920e206fc0c82165a83b32c42bc29b3752f1991f454f044c3018443d2d1469
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:62a96727d520cf929e6615015259c4426a5d186c706597fc42d51e2caa6f70b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:4a70b53ea2cc08d205862bfc486b5cab93b6b307c102a1deb2c89e4eaf636d5c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:3d18e4344dbdbff89fedb1f18f3a9e95bb82fd8061b999eaa0a3c5f4afe2eb02
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:1fdd08f0b6c702d4693d0a2d80e83532e65c9461ed54b90670ddb251f29c87c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:67dc80688996f58d6ff3bbab7890b6c73ec3833997a7578f381de2a2be631245
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:8cd69456a60029697e025c9e2ab7be87ba33b6e4d8cd7e93f8f799675ffad69c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:3b9c6541d74692681f9774d9cf674b8e7f4e386a411583bf569644b64b621227