Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli)

CIS
linux/amd64
debian 13
Tags:

29-cli, 29-debian-cli, 29-debian13-cli, 29.8-cli, 29.8-debian-cli, 29.8-debian13-cli, 29.8.1-cli, 29.8.1-debian-cli, 29.8.1-debian13-cli

Index digest:

sha256:e9e1b5525091820dc4b391d21d222e2183a45ad0d313b6ce9cfa247f5d18cd45

Manifest digest:

sha256:b551463c5fd747f3af7a585ff57dafa20da10104a4c55c582671966f548ac77a

Size

111.29 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:c835637460cd17ebcfbfaed0bf6d5a684cb0e9276855c2f99cde573ddf63a2b5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:d9a4aed12949d396a04f57bc60350f6e022ecdd7f86b9fff51d4a5cf40d905c8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:43c139dc5f9d60dc08abbae2a5bbf314f4a6c6eeb8b735bbb98321ed658cbf79
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:14b41b7486250621d4b96689e353ed615d422cdd82d792d5fe3f6013311df9c5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:38610383366be297c42e478e06571e29f6156b4758d90025493ef2564cd16164
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:4a78c863d1de032356c7a2488da8cd1566ac51cec64d8a44fb5043e547eec927
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:e377fa40fffbff8796b5272cc8508a45f3692fbd9794fb5d6edfd65d316b41cf
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:3fe74d09c717f6ce35c98ef31950b8deded710abb7b8560861ee9641fcc438b1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:7c3772563f6634af583f56504d58983e443c07c8ad4c52332cf36e923043c1ab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:b1d43fbed9496a7de5250d5c03d4e59601214db5f2b3475b14295a268226277a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:89212f4d997dda0a3e7f12e90369003c7a3dbabed352a42470b8090a150bd819
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:0d2a37abd89c061ab84a08d7b612524a51c78375c9c161a914e70d3662c8995a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:bce4ef40467f85ad61bf9bb4d730696fc1a13c8bbd30aed46644be40597e036a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:54ee5a9d30e3422e77b38db8f837e0525a620d93987348ef2dafbe7f62bc714a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:f6eaa99ba369cf56bdd5a61941a19b04f9169934775e9f5e823d7195f8cf2b6d