Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:dfcd58e688746158a95f55bff8af6c66cc898bb5af85c243ff1c954e1522e24f

Manifest digest:

sha256:82129b6790392163e8ab6cc1ef59eadfab527ec075d02c19ce9ef88d372d20bc

Size

24.33 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:257e881af049d1c9aac9e8c75de58fcd11e0869812f683800a909c613deaeec0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:b959c1d3a6f7987fcc3387bc536cbf1b8c712c2bba45e78845679971ac5ee93d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:76c2eb807c3f565c3a4fe45992fe8a5ffd40c2fb1f4fcfe0ad5750ce25dbef17
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:716d8aaf7d6d15fd8d09012453fe13ad4851595ce3e12e7d34250849d5a3c250
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:675ad4a176258decf795c66eff0b666e570a4ecca9de869c1469efece7ebaef3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:1b7e3418f8ba2fbc85273eba3a1e77416e6d4e71b1621d033853741c6b234d41
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:ac25ad93368b0d22f36bc09c40d7376ceff203bb204542f522b0888ddb401593
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:8d6ef4a435b9fc51a38d2992c2f85f108f61d86c601daf25099ccb064a182c17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:f213ccd481fdb18ebfb501251c8ce9d727eb4dcf5632e5c627d5770cb4a3c4e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:6d153c569c04e343d70192fab153001a9bd9ea616dfa1fb4aba992ba7151b6ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:6b00e5453d1183fc3947de931225c4437cc544941c39dcbbc230a19e4b15574e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:127c2e97baa8b97b07428bfb6a43e16938fef4313b169d621d595af06d5f2c64
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:69d3080729e081caf69c15cc5a0034a062fe023e6b266b5fc1785f0206098029
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:f1b8c6854b68cf30ac0a125a83a03c7323dc7b3963582dfcf6cd182ffe43ddd3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:1a32dca8310a4846d769d547c2514a4358a6bd496f2d68d9f138a326d81f7f21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:93302946dbac1f2e2df31aa50436106932cb249fceecacc9987856952dc70b53
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:5a420368a8d73d15069d6c9d406a90518eb54efe4050b58174c7777bf113554b