Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.6-debian-fips-dev, 7.6-debian13-fips-dev, 7.6-fips-dev, 7.6.5-debian-fips-dev, 7.6.5-debian13-fips-dev, 7.6.5-fips-dev

Index digest:

sha256:a7e15513b43a18f92ca35cfa987dcd6f01b3ac4524ee4941258c192427f16b2c

Manifest digest:

sha256:3a4e66ea092d50fb02a7d36ed80d58749154226300d3ec586b3141eafeb68afb

Size

78.44 MB

Last pushed

13 hours ago

Vulnerabilities

1
15
16
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:da9232727c1faca465617fbf22b21864cdf38b00e28c58b5e38286c7acde204d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:62ed036da7ffc46e40174b1f7623b8f7daa0bd0be11e463f7a3c6eeb7755fe60
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:3d366716f2270a52317d2fe4fc9b7293876faae8ef0dc3534a5eab82b83efa6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:39ebfead02fd86460e9e8a4be9676470de58f0965bbb5ecdd21f3bf5ad6b693c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:f268f7b2bfbf4fba0bf259870bdf1e243ba732a7724bf5a873ac9205a3cbfe2e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:1eba6fe8f9ae95f12ebaf1bed5047b9c3ee5f61eca0cedab8e4deaf4ae19967b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:1dfa9a2c0b2df6fe47e6dd1784d260e724efaf1a76eab59ee24ce1f5937ee5cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:22e8b3a450cf8a66a3d6116b40b2ca1c39de3db169b7a3f211c9f20283f7a89e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:65757ce60d487cf177fda271f21a15e1c18b892af8bf8701b145d68908b0537c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:0274337af4512370cb37ea7f97bc689f7cdec8fcfeefdbd58bf0dcc8b062f050
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:af12f7b7a3536ba5ef402db4d49aaca8d9e5e69dc1b4ce48c9c5f465046b4126
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:15fb3f6ae16a677a7f122c96926e9fc62a81a73629624988df373030ae1f3e18
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:c82b410a5d7eee9f098d5d0b7fdbd4c42e1a1403376c294bde59cf6b4841b9c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:7fc92a77139d30db1b5c0e4397dd7cea3912e0f369d78c9d06a3cbf716530037
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:b82352d82648527a4a504a924e96458d53206ae18b1d2c99a6675a551c3b6a34
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:3d65ec94141feeff12abdb2092f76914e3fa525ff42215330043db81ddbab7a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:1a9c80e72709564e67570a3a2834565b4acd43d74e81b999f47d2d0f74e5f34f