Sign inSign up
Unleash

dhi.io/unleash

unleash 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.0-debian-fips-dev, 8.2.0-debian13-fips-dev, 8.2.0-fips-dev

Index digest:

sha256:cb7c0655e01942b45384132e3d14c8331fecc69738d731fdb620ecc072ead68d

Manifest digest:

sha256:5497a126e30f8f6b3ec8bec3cf0c7db818682bb34adf45dc84eec4ebb545a918

Size

82.71 MB

Last pushed

7 hours ago

Vulnerabilities

3
12
9
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:cee401177478e9d262455f0554f92b17a318e0f6df58cb6fae6de06c9d483656
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:3052dc519fcd5d073bb1dbd69ab8604da455daf1ed2da6c760ea145b09205cf3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:b8d931bc58f374f3a64d9abc6cd05f3c7a3a3fd16f359bd6367896b0a552b1c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:0db7bce4fb8ca61a1a0c71b036fd26109778dff17e36941c26e695b9e5ef951f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:a23e3b9b2727679800c944896bda3ac4a71ea9aaab5da78f5270b3884f740783
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:383a4e6b7071650ac70674d86794d8c42d233eb5eea163588104a2c2e3496304
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:884555bc0387f670ac0d8d6ad1202df6b446c259149aef9a5f2824c22a8fe320
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:14e4c1c2d7dc0851eaec55f0406024cfac49faaf3ca4723e81099c5d1ee1de07
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:fc01ce8e056ad49f1c04ed017a36e65a2388b86fb1c5f10ce5c2d373eb00310a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:f04182a5e37b505c3622da5b3ac78eecb2d7f6c264fba1544b5373b9c8d11212
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:bad9cc4deff075692544eaeb2b33cc963d4ea556f5da7839577b547ab9773865
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:e260694f3b2a924ddf2b213a0c0398f2e0f166d276d6369affdd698d484eb2cc
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:51c7a6ab6f94df96fe6fbe68b8550ce7d0684cdc708d387ca7d995d01ffa024f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:1976906f4e3cdfa904545c11e83a02abe27ac1e8313d39f45a9b6a2dc32ac102
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:2b249b588b7f4b8774d93a72676fdb3f0f12447ec57554f28950f556214ba89f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:a55dcbd7aa297e08924830610cf1ab1fdf08d65bf383695a55928357a71012e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:223d850a7ebfa8e6765001e08dc5856ff0769033e6905fed66b79cba98aac67c