Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (dev)

CIS
linux/amd64
debian 13
Tags:

7-debian-dev, 7-debian13-dev, 7-dev, 7.6-debian-dev, 7.6-debian13-dev, 7.6-dev, 7.6.5-debian-dev, 7.6.5-debian13-dev, 7.6.5-dev

Index digest:

sha256:5018047f0aeba039342fabbcb7e4b9a315d07b0f2250a1ebd400e545a3cf4ac2

Manifest digest:

sha256:c06db92fbdf33c1780c08121751f65397e82b62b4a42c9e83c45bd8b5ab63883

Size

77.70 MB

Last pushed

12 hours ago

Vulnerabilities

3
19
16
2
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:b1b11f4a477a61e39e823cb7ccb172b128bf9c47662e6d767c6eb00f71974408
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:d290d2f5017512d3e955a81c6eb9b4704aaecfb9e8ba7c102b380432882e52f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:d4b8b90e84bcc2b2fc2b5d122cdcbaa41cc7133c07ea84b0c03d8760d73d0b7d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:00bbcbad54147d9f796b4962235ab56cc84cad7bd60dd7cedf63c6337a47810d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:351e14bdde69316b1ece0b55f2303ed401123ff651ae12848bfa053b288de0e6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:ee7e66a16f30c28d1282afbdfde8172a380e0927d5f7108b54b47095a24e8432
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:9abc73f2c21124c0be2f1bd73e37a8b306201ca07cab5335aef98e3885be5444
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:2ebbaaac266011c9704f96f2370b31bf5346831a1b156b607a6e8768fe7767a1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:bb160cf35b16bfc059bef6f7ef120fba11ee752cc3bddbebcac760b82971d6fd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:d1838c1c07fd7817d0b1785e26199a300b972c343dfeff3ad32040bdb1e97019
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:67f9af5598d4a452a2252476817e671e85272e4ffcae54e86ed0c9dfef001df3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:95ee60cee40bf7a70a1fe237ca5f99345b03f6c592b3d841fc407daa938be3f8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:aab127d3a6242b3cb1552a2342697693d380306e28837471fbfb662e9729e383
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:f310e4f61a2810b679217d9c20fb0828e2884731978c6b859646b1cd01a5ef91
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:6f67555a09f0acaa755406e56a1ea4d06c89802a4c173e131aa0194e8ef29610