Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.1-debian-fips-dev, 10.1-debian13-fips-dev, 10.1-fips-dev, 10.1.8-debian-fips-dev, 10.1.8-debian13-fips-dev, 10.1.8-fips-dev

Index digest:

sha256:5cb195334e9a448f38ec569651f3338884724ec83b44922f13f4e0573b9712d9

Manifest digest:

sha256:1185a13f566eb9a5f7a7c1398944cb3647a545255cdc2efd20c3fa4a59b5c015

Size

36.09 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:fbd24ad595172ac18c52ec3e2bad5ff5b364fd4252b4f1b7d05a87343f67ddc5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:65736f391d55d05b8cf540917576e87890e24a0f90ff59886f46f1aed66ed37a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/polaris@sha256:cc51dd6f1fc47ff9644cd30e4a69f9bdd5bba4998a8c8258cab3db0c621ed42d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:51b4e139836724bdeef154c4c8a2f8700e0d7c89fcbee40dbf4d6b6e06f3b9d3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/polaris@sha256:4bc893edf5a6ba1fd5c9aaf6e4c688d333d7cdc578ecbbc4bb002ce424df8c37
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:5df348785223294073c3ab0764378a74304f35c313044e49f70227d66dc5da72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:b0a7d10bdf4e7a2db82d9ed5eccdf8f9c6c4c7d0775b4d365dc0c3a634661c7f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:a7e77ba0534aa93ac671fcaf4d1bfbab696190aef13d71f35ca83668525f24da
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:e5ee40ef976cac002d3b3bc38b18a4e757179da79a995197684ad28c38c3bbc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:52bec5f701278089991005e755a537e92449099c7fa4062cc6bf0d5bc44f7289
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:40bc1032ae9ed85cbb1678983ecb89bf8b177ed0b7020b80f26726a9f398c4e6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:29a53e00d128d87d87cd50fb719f12a3265977dfec0b2d4c23e5d0129a59884c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:9b55c30e36b0ee87771009ded81f73ad830d96e58cd8b44b44b6fefc76f02df5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:ebffe4f69768b3f69c57d53a6c570a778518754d51d2216f8dd464fd404c7162
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:1953f7a41d5ae226b4615ea648010afc68d35b1021fb6cf134821193bd380f12
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:3cbd802ad3117573e3b7e20a877a7c02e8debc3506a419fa3a5c4f31b207dee2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:f0b4bbfe521399a59851add559e8089a18cdffea8fb5dd6f1be8ff7fe9538382