Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (dev)

CIS
linux/amd64
debian 13
Tags:

10-debian-dev, 10-debian13-dev, 10-dev, 10.1-debian-dev, 10.1-debian13-dev, 10.1-dev, 10.1.8-debian-dev, 10.1.8-debian13-dev, 10.1.8-dev

Index digest:

sha256:d49397298d3f903e262513e173c0df715bb5036d48bde75ae61c4971622367af

Manifest digest:

sha256:a770d908bdf4f54b8c7e8810d83900d82a996e1836c12d7202ce92f4235db4c9

Size

35.33 MB

Last pushed

2 days ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:2fb54e6ef2978ab748106a12a6244b9b7dd8edf85d326e4043e84034ccc006d3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:7a14fe9d57de4addf7e3d86e3857ab8e0b9f6ef361251bfb82d8f50bd8ff5325
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:cc28cd13d97582ed8523a99bc1f08dbe4930a63afeb28ad7343100471786c366
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:362b7af3a0f180e0f1754a1bab83aeef16ff9224da998d53fab3e29b01e42a1f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:50f535ecb14e2ddef01fe9ddc83de5a99eefafe8f244faaf798b4779c2597e41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:420783521431cc65519f7c761f698bcc0f7c3f4e4683b34737903fed4236e14c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:839193e41702bfeb50c4f87d120c2816e4441227f5eaa0b0e97f920f68d0884d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:8ecdc45df4089f560db420f0718100bdad9ed697402455a0b55180f2b1eb50a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:3cc08c7b0a08b66e13fec4b4e907e23e0aa34d282c96e265ebafac637f9275cb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:bce4fa206a56ac2c433f51d49a7f45927dbc961c5e299d5bc325f1c569c4ddbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:919554df37b1b04a40ac30a0253583c89eeff23911bb05650564bd46b63a3c8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:3bdcf61fbbf2c0f3f643398c4cf926d3c4a7f7f7b5eef90585c5a47be7f5bf79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:b0ae11f3d9b767186a8183603f765dc4d30691b4d23773e2f622be5108537a57
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:88634ec7035914dfe5ca5dfb42ae28a2f74a5228e28e553ef7d239c5b67aab72
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:ec8accfb7dcd2109c0d88fdd8591ea64337de2e922bd50432e92887da91980e7