Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (dev)

CIS
linux/amd64
debian 13
Tags:

7-debian-dev, 7-debian13-dev, 7-dev, 7.6-debian-dev, 7.6-debian13-dev, 7.6-dev, 7.6.5-debian-dev, 7.6.5-debian13-dev, 7.6.5-dev

Index digest:

sha256:faf173749fe8ab5a781593f9090657dfc5eb0c03bbca207fadb85dade5f4b5ba

Manifest digest:

sha256:530a28972ad1d6c5487cd626c7b49d14bf42e52a6dbb95abc1629fd4c3c9087d

Size

77.70 MB

Last pushed

15 hours ago

Vulnerabilities

1
15
16
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:f3172a9ed968c93b4c1ea09be09e506e086370607c0c4b275aa507edb3233ec3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:3774bd4188f9ba622a5f92a8823bf7d718b2f9f1e7d5606e6f20b477a629bf21
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:953ee77c65b40d749632a5b7205d0f9a831619a6b7381a77e308715b9286467d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:0050cc213f3d14a0b7c9f58e4b32598f46efb5218a5db9c978f6b3ea65eb3cdd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:6b93c2170c6a310d8d22f8ed4ef9854186e61f4f9367d08f17a35b581a972fd6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:63817b7fdf5cc3d6ae2f7eb3fae1cddd9ac0d922178aa6cda2317f1b5d38103e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:5210757459bb83926fec0617afb405eeb7e4d8a4fb0c1435a48545ca0c223128
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:e418ba3fef58d70f60cb4ee1567777c2fc26177798cdc5949b2a264350d4aabb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:9ba7580786c3a75ba7b813a35e85ad49b6ace4c59a4d4e6998720f6549dd4a95
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:5b57496b782b1ebcf06d6ea78c16ab9fbfa96ab112974ca5e2a3e20353d6276b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:5cb5565c8a6fe49559e2fd9dc3fc97282c439421c48e785af8304589c5b8e2fe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:f0b9ce21d68b50113c9d35eec4b53a07254ae5069ebbb50a87ea277a3b9c204a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:dc8f0256c3f8d03eece573bae013381e07ec41cf4948a08f295f9447fcf6cd3f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:1cc5eafc93227104cfc67e3be14cb9d20d21c47ecf843dfead4b4c9356e399c6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:65e12069b81f7657d6dfab86da84e2b70e0052b5ffe01463c06f792cecf1a213