Sign inSign up
Dart

dhi.io/dart

Dart 3.x

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.13, 3.13-debian, 3.13-debian13, 3.13.4, 3.13.4-debian, 3.13.4-debian13

Index digest:

sha256:856c13fcf47cb8153447e7f293d02ce7304888764c9292643fd8fe020c3ef8c5

Manifest digest:

sha256:2ca1b7198dfa0643553c10cc9152384bf98801465ee36903e9354c0b9a8ed8a1

Size

205.91 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dart:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dart:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dart@sha256:183c5a263f064c32fa4f81c69c16e4696e48239ef5ea65fb2b240447addfb63c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dart@sha256:284f5e7e8d1c0483ad63ca2fb4a283cc79359981c250db58e16138eb33bb217f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dart@sha256:0aeced282021757e8ebb5c71c9c1afe3ee3d45c5211fa22ff5fdf07a98c7c364
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dart@sha256:3e8b4f2200b4c4190345aaac0c11b3591ae9182c30cd631b0beae5bdcf793113
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dart@sha256:3da15e3fad8f459ee4d5fcbebd267f55433bf032bd740f2360b7f78bc517bbe1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dart@sha256:fcbe6815f09c5ba90ed6a2ab7109db9fd05c442ac3ab56575d89af5ba0015e10
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dart@sha256:de0f0471fbf3d8b99d2504b83ee86660bc688ceaf8f0ec1fb65defc66c8bddb7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dart@sha256:cbedd5b7b3ee3658f75bed4d975595b981217140d3071116dadf2a9f240152dd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dart@sha256:4b800c868da0b6a9e8b914b9a77527804ea52140a1a497d8f248b8cb12ede40c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dart@sha256:c2ff44aa13d8245e0f49e862d1314e153852956421877ec37c25d94285dd9908
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dart@sha256:fe0191e370cbe681bf16e9e1804a2ec6ebdc5a649b7a352f3e39f4373221fe6e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dart@sha256:23ef6902c336250243938d1980df7ea44d00b5e8db7a6df9cdd91abed7d2d958
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dart@sha256:758abe670275cc6571ac5fb14a7f944c51b291b03ff2837da5dc2328fa0c0e25
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dart@sha256:9d5674ee028a457f96a43e67e03f84a0de57686735aed600bcae30dfab1759da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dart@sha256:31ff377da8d97fea24032172ae2c5653ad648ca1d666f17e33372b36e58543bf