Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.1-cli-fips, 29.8.1-debian-cli-fips, 29.8.1-debian13-cli-fips

Index digest:

sha256:567f8bc12717d0c46b4868aa1cc7bee06f6976bbaead112c0a89332c9a333a95

Manifest digest:

sha256:b4bbe9b044faaac7ff74742d00cd6d6cc59ac3a07b860f09188cb7811491b2cf

Size

111.81 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:bd2a213b0b00b80e042308e79e3a54018e3660605475c86ba7b30dd74a864492
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:5fd48e592d6d14fcc029fddeea5a4fa98755f8e53c0b37b84a926e0c0c218eec
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:1577f04c0e8cb5b01bfb52126f33d86f36358ca7766d2949e421ccae73f3aa63
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:d6c8afdf4382f6ebeec89944ed1c32c3ec14d2d9c753e8d217919eb01c25e0ea
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:bed769a101f3e554e0e956f2f400c6a5a9582404d66bc85e32d3c2ccc659b437
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:c533aecab218f67cacf405726863d5159098e78e127f30b0ad84d30bbf788a1c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:11e501a8f3e90be3331ee964a31a94d7daf215d020a531b94823fc918828d220
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:e643ca0e9b0d73a0ead423e89fa07ddcf1b77f8d546313760bf44293613848c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:ac7e3d12fb5abf5169e7510baf5b9851e4900ecd2f5428d6a16d752421f1bb5a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:bfdfbe8efa3b3070439d2d918096bf1e6fb3b0212744e3b7de788b95958a8d87
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:718dc86313fc4d5fedbb9e0d7209987890ad0b2b9955017b7f43b4d2fc536cc2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:f4b70ca3c74a2e79f891f8650408cddfd6facc15e5ca65704045376d77d3d860
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:fc2937fdf567dbffd7c5ee232975a769efee0647977e0d8fbae210795b9c6c7e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:d2f7a331f55b2d45df8343c3d54d8b6f84d76aa31f33254269c494d28c5be31b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:7ca80cbe6058b6aeff23c7868620f444e0dd9611c4397a34d71f829915e10679
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:96d9ff00cb825fd308c296a9e89e3347a8100b30007ee548c3dc7d4db3ad62d0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:816e62559f93e7bf58e1476f184ef821ce8c4f7351f929fc8ff7c07bdf9b0c4c