Sign inSign up
DHI Build

dhi.io/build

DHI Source Build 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-source, 2.25-source, 2.25.2-source

Index digest:

sha256:a08ba2b8894ebd5ff0e2ea75bd43594e73320f78d626532d6e5ef793d0a28727

Manifest digest:

sha256:454066a54918175e42967ea884d012ba70f3b6f94a1f3b038885539672b776ff

Size

117.63 MB

Last pushed

13 hours ago

Vulnerabilities

1
2
0
92
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-source

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-source --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:e1c36ed86d1c3298c17688dcdb113d72406d5c15b37cf224ba3af3960a614ee1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:e5e45e436fdbb72e26129a936db9460d00a9f2cccb5c9ad9d54a7b228c3d2c31
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:cbe52d2ea4d0c130cff0ffc372c2c1d8e5587a4223983d1999f37486962d3531
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:dc46d490bfeab4460399cc3ab674d9eb14064f6837e35544e2e1dd176893ad68
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:525412f0b12aaf119a17e4983aa00f7a01ac3d9854aa6caf1831e5c009d7d943
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:dd2357076357821724bf90d19ebb32df7e9bfd86a3bd964521bd8f156bcd5bfc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:4f43771a3c66d339e9a46f23fcb3fb2c1f1c150a6c9d2fe71121036336a7292d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:6d5c52a95f6e633f75669d12d6ba84d74e6753690767702c6b4e7251df9a01d7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:9eec8582002827fc2a66e729134a31968d910d1b43c9193a89c07dd7b678e9ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:7cf71474bd09f98f6f17e5847bd31972b797c5b2d4b5d3c5aad21001cfea6db0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:10827ae3244f55e78a824b5c957fe440cad1ec0a2f6b9e4dd0000cf6a02378ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:9b31bf3ec62c290f0d8767ea2917dd2e63ac77a19bd801eac1879b280942ec3e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:cdf4f85c47f16fb068617443841ba6794802b182f5115e7ca136eb73f9668aee
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:e262cfb44d2b202a0e1d0c6afc07d5224d4ef3acf931594179b5986ed61ce86c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:cc3ef656d24a08f5244da2efc1e552761f8d960c78512d0c4af8dc0b71edd54b