Sign inSign up
ORAS

dhi.io/oras

ORAS 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.3-debian-dev, 1.3-debian13-dev, 1.3-dev, 1.3.4-debian-dev, 1.3.4-debian13-dev, 1.3.4-dev

Index digest:

sha256:fd503c36f6ed243c404bb671c20dcca5d2820079fe99c3e865238861852c7d11

Manifest digest:

sha256:af8f8e72fbc561e5e69a01c75df44bc2ce9183d8a47975b07334b0e1d37b4a82

Size

31.43 MB

Last pushed

2 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oras:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oras:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oras@sha256:a657d7ddc87548e6c9eebf25f07c2e4d4201ea1d263f29006343bd1b2fadcca4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oras@sha256:f044efd5a7672dfe920a079c78fa68770f4be5af38ec89a1aea5926c8861dc6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oras@sha256:490fea6f7c158731c298cb89a8df6db90565364a4ffea222f49495cbcbe7013c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oras@sha256:dfb09746eb8f5a58c9f46ed7a858860b6022403e0e482026f534001587c36789
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oras@sha256:3042ae83220a4870b6acd8d019f7ce1a89ebe6b7a791e768a7f44ca51862bed0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oras@sha256:80ffde260a87771bdd905f906c60622bd362e88b08e7d425672c2edfaf035e2c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oras@sha256:0c31162cb20555feca7de43a671d3195cd7dfdd224300ca0210589527298a893
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oras@sha256:7cb801acd8e193df35e0b4e161b1fc7d532d8a51976a6dbba519eabd3c5f4e4c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oras@sha256:62c888dfe14ec86d2f70bd4b18ad86f46c7b919d957b46955b7b58c8287861fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oras@sha256:3395dee9f05a914a94e39321cb942f8902e66acbd7abfde93402aa91c452c71d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oras@sha256:dd843d59d4d07f1429f57aeff7ed389e316f47e4ce37ceb5679b0bd034600142
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oras@sha256:e09d40fc1d9d97afb3270700ceba150abaed41060100f93689cf21d97bb44601
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oras@sha256:5cd00b9ef77f5b58800886fd031fa37b96bf92111ea69e469cd070950a25ab0e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oras@sha256:84c827420560d4767ff8974dcc782daa48f63bf5293bc7ee6afc26770f04dc86
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oras@sha256:6e5be5f3b97b22e777f8f2998eabbf77b16ae0504cdf1096f2ea678d147d15ac