Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-debian-dev, 10-debian13-dev, 10-dev, 10.1-debian-dev, 10.1-debian13-dev, 10.1-dev, 10.1.8-debian-dev, 10.1.8-debian13-dev, 10.1.8-dev

Index digest:

sha256:ecd733b252d0c863e76f01e12ae4d01ec5a40ae7781211ea50e686ed9b350070

Manifest digest:

sha256:56948df59409102c21fa5f6c48229a0635eedbc6c91082d4bcba44621e8e8daf

Size

35.35 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:783bb77accee22781e5425292404c4087beddc25dade32f1a25c3a5d4c8131a4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:8e1d80f2b824f374520b9d6c4e3ef70e6a257fe084bc82d5610ed1070cd8559c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:a20d9ea2bdc4982f0b669b4f8f391357a3cca8a4c986cd58a2f8dc44141c366f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:745c003d40793ef6854731a799b29e150db73f94f19fc5d12383a0fd3d2c5ab8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:978a668e5f13f4765c7ba44220776fc694b4ed373b2b711df1c1187c8c80d3ce
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:b00116fe9bde2c403985be71dd8ad0ecfaf6434f85421965335b831b64d7164f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:9bc6b166bfc826b1b2d3e03e80512297056d6068acbba657bcd227cba8f49812
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:23070a067574c3488c8d29b6a0d74924b31ab8da3651228f0e9094fd1d4c9ffd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:8b98002f338c92d3625cbd5193ceb1f5bdef8f2fa4f05b0af545973902b167e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:4d7a5f4f7f8fe355a4b2fefc501d55c49a8a92df3a718189285f9936cd02c48e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:6f6e6b611d1c26e4e19a9983699807d240a89c3cff280d63912ab207a9eb3525
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:f2a8c7d011cd8f44ff2fd313e8f6d42ae5c2e040aa9f2ad5fb1542f05deec853
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:d53478319b8b75efe667394de59b79f234459ecc90a5057c194fa6d7287d06f7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:085e927cad7532ce005ee44ce4cc6ee1acef38a88ed5b07a3acc0c4997be69a6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:e16bd40e67a7c6ca9eab4b5bb92763cc39a5694ce9eacf8a7be7f61bb0e2feda