Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.6-debian-fips-dev, 7.6-debian13-fips-dev, 7.6-fips-dev, 7.6.5-debian-fips-dev, 7.6.5-debian13-fips-dev, 7.6.5-fips-dev

Index digest:

sha256:bcf9adde60e0ee8bedd6f028885654c36d7a89070806c951a2b48b79b4dfe331

Manifest digest:

sha256:2b60c9d6b99673d4fd5b60bf1965df99c8bba2b4f0ba5831260839df2de2fce6

Size

78.44 MB

Last pushed

3 days ago

Vulnerabilities

0
1
3
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:f0c9265484f56729110e98492e88a8dda57ddb5be34195592f8071f87becbc0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:a849692da25f45455e2887a58a1e4ac4a46b0b5145a91265ade0568e67632679
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:0a5f6c0bd1a68d45680077b8987685f1dd3b73cfad7c05e11ef1f284b6490bbc
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:45a02c710baa54bae623cfc7735242cce95328dd21ae629d3e7c37538a25d9a2
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:d159072ac48efdb5157ed2b21cafcf7e1ec8105259558e79f5b35426f476f8fd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:ee13133d3d5f552d76123a945956fa97f40f9dafdb566fd2f0749f6fc2d2d5f1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:b6d8c95ba6900630ad064b6b8e9d42acc032b1e0d5dc3f78ef5506877f14c6a9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:baa4ca11182c27073da2bc45718d4b1ed4f35674657068c69076058818ba3ea5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:fbc6784016a57875f411d9404673e115efa773fca9a849764243478787621334
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:fabaaf8b91bf3c59d39fb01c87fef5568154b07c988f988edb91ebbf5dc52c07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:cdf615cc18af82b2796e84a59f587e622dc186d60a4d651d5a275cd39023610c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:ab47099c23a4f0746c34d7636190ca8f09f92be600429a39a643c97640573e6f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:072164e9040fdab1dd89a9bf9eeb2932ede6466fdaada45c6d79aaefdcaa5113
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:0766fc02cf3aec3c3733fa31e8f4ed5f6e30095747766281c6078feaaa474dc3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:2f51d99869c858c4e3799f6fb8c5998aef7ae237269465a87410252c0c882a62
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:64776bdb34691def332274f347381ae382f38b234e97f392f23953b0ad3fb9b6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:32ff972b6262b24ca540a2e30c3c8cf3342cfa96cbb355f921b1f93c157d9cee