Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-debian-dev, 10-debian13-dev, 10-dev, 10.1-debian-dev, 10.1-debian13-dev, 10.1-dev, 10.1.8-debian-dev, 10.1.8-debian13-dev, 10.1.8-dev

Index digest:

sha256:6159e363ea8899fe1cee150ee400df11dd3160dd86a291fa61b98f72c40a2ad3

Manifest digest:

sha256:eb39cbad1c1f87ffb8406e4752b4de15127cc502a1bcca9dcf0c7b502f2bfb1b

Size

35.34 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:a60c4894b0d08a7549197b243f09897c79597d17a829889f0b17ae56d9d6ae17
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:b7ebcc82f892c79445695a6b647595ce08861e8f78357af48fbf5ae554936629
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:f0c61794701ec221460d4efe0e971de0aee91be8c9c56a3d18f015e19d335600
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:411eb896b67d470410749aef85075d203e15d1e71e55ace02ee0c1bfb94eaf90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:b75a56efa1be0585ff674158f00976928feccab2682909d2db98c390de603a55
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:dd70dd7b3dcc894a81542592d8b57725ddaea06d41bf58fe0fede9ce5bdf784c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:3c04af18924235006c755427f42e08bc1379f812d33b1c7eef407e89009bd3e5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:7ebe33c33730ef3c38cc64d8940ada7f75c47286fba0bac4d79596e5b7e280ca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:232e8dc1dca35c69f5a7ea0c8e23554132f6385af804bafd7166053f21c620c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:688ff006795f0d55166507f1fae0d0b38e88f3c1cc3aae4fcc634ff9a34f40c0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:5eb98c5cec25973d102ed40d9a672557bcebb3d70a2d1ce92696cea39d1261cd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:8786fa6b3543a4e4f70a2b97f5601c48f2e25edd4cc5c879e4305e422079a13f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:6f4e014cc481ff92bf0babbc12b94245430140983a08ae8f4f4cee8ec3dd9c33
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:6aa225f897682b22afa2232ede34e891f0e74bcc82618b1a7bbf308f80cd1eae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:be0d23ba5419b112fdbfe52863d70dd9fa455b7d2e36c49428ada69c3edb3b7c