Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:50618300f8544f54a083d623488a9437aed7c2769c82c9899a4ac71929b91d05

Manifest digest:

sha256:2cdb5e058cd3df3f0979f0dfe602e705d92cf307709bbfe0dffa197e56df88f3

Size

23.58 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:2c4caf7d41a13cdd6937b0319380590a0721c6b4bac2ca2b0dd5e6b722fb7252
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:0828ee8aea42ba1886980df692e185ba8ee7e607f7f22fd54c90a95cf40cc080
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:125f4f1993a1cec049f99b558b2d9b546283a253726234d459850f6ccb745597
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:ea713101ced70115bbbba997ff8bf0497afda31589322bb862019b0bbec63c63
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:aae91058e8f2260c9abe42dadfbc97d741f0725efbafc00c854276aaa1cd9fdd
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:cced3bfd33136808ca83e7bd2d151b4312153a180661a96617473647f12192af
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:e80dec931ac87fc3ef951a82997926ee6a4165c06a7634dcdb4c54448c50a7a1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:636614d0c1704d7456dd01dd2e4fe8a572ed9e313cf8401c49b5a0961e82dd09
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:f2e0e8e93cdd39e2b7e2e822ec75a3c6402b772201c5e304ef9c6edb2a58bef4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:984b340185cc38f0bc29a0acacabdb35cd1ebece52bab0407b9c8145d2094408
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:f3e1b5c5e188e27a338abb0e34729cde56fcc2033f4a5474afec11b6a35e7017
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:a39d730d8aadffe44d0f319332da655b090ca630e47500d616cc5d791ba01d36
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:b23c1196c4609b5bd82c17046d1c70ed68a84faa645210bbf2f8f2aad8a06d4f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:e9d62c0a04f120da304bd1b2a74a4c769a319548de668abf2232ac0df5798cc7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:18c006e5865cadc9a872f47cf6c1ed258ecd724bd6efc423b4e3ea5d7c9c057a