dhi.io/polaris
10-debian-dev, 10-debian13-dev, 10-dev, 10.1-debian-dev, 10.1-debian13-dev, 10.1-dev, 10.1.8-debian-dev, 10.1.8-debian13-dev, 10.1.8-dev
sha256:ecd733b252d0c863e76f01e12ae4d01ec5a40ae7781211ea50e686ed9b350070
Manifest digest:sha256:56948df59409102c21fa5f6c48229a0635eedbc6c91082d4bcba44621e8e8daf
Size
35.35 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/polaris:10-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/polaris:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/polaris@sha256:783bb77accee22781e5425292404c4087beddc25dade32f1a25c3a5d4c8131a4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/polaris@sha256:8e1d80f2b824f374520b9d6c4e3ef70e6a257fe084bc82d5610ed1070cd8559c |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/polaris@sha256:a20d9ea2bdc4982f0b669b4f8f391357a3cca8a4c986cd58a2f8dc44141c366f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/polaris@sha256:745c003d40793ef6854731a799b29e150db73f94f19fc5d12383a0fd3d2c5ab8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/polaris@sha256:978a668e5f13f4765c7ba44220776fc694b4ed373b2b711df1c1187c8c80d3ce |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/polaris@sha256:b00116fe9bde2c403985be71dd8ad0ecfaf6434f85421965335b831b64d7164f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/polaris@sha256:9bc6b166bfc826b1b2d3e03e80512297056d6068acbba657bcd227cba8f49812 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/polaris@sha256:23070a067574c3488c8d29b6a0d74924b31ab8da3651228f0e9094fd1d4c9ffd |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/polaris@sha256:8b98002f338c92d3625cbd5193ceb1f5bdef8f2fa4f05b0af545973902b167e7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/polaris@sha256:4d7a5f4f7f8fe355a4b2fefc501d55c49a8a92df3a718189285f9936cd02c48e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/polaris@sha256:6f6e6b611d1c26e4e19a9983699807d240a89c3cff280d63912ab207a9eb3525 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/polaris@sha256:f2a8c7d011cd8f44ff2fd313e8f6d42ae5c2e040aa9f2ad5fb1542f05deec853 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/polaris@sha256:d53478319b8b75efe667394de59b79f234459ecc90a5057c194fa6d7287d06f7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/polaris@sha256:085e927cad7532ce005ee44ce4cc6ee1acef38a88ed5b07a3acc0c4997be69a6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/polaris@sha256:e16bd40e67a7c6ca9eab4b5bb92763cc39a5694ce9eacf8a7be7f61bb0e2feda |