Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:f3bd649e61fc5357c3b2f207a0b047961d5562f0dc9905b85adbf4fa19580292

Manifest digest:

sha256:936d6457795020f99e27280708bed34616038a4b5970f34dcab68b286d78947e

Size

23.58 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:9c21d6a9cc65411b439e8b76d315f852525990c3b94b7f117380d6a85297848d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:48fb6fd7b3617aa59d274a529d6bc06f5f757334850d4f7e5f8910eaacd4638b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:82476fc9c2b7c5245d156462e8f4601b11475a93ff2f79313e185f6cfb963156
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:72c46a69a962b1c7796afe8e3455f4d88e1b1b2bc156a59ee73d6a347c968ed0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:df3b8fd17ae03df36db3869bce8c05d536d73c3141da3c704cf0c0527e34929d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:abecd047b3ce59c3077d322e4ff9a1990d98b44ad0d987c07c6e4f674770b540
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:4cee80e2cd72b291ec7347aebbdbd8e728ea489b7417ddb37dfeb60e607faeb9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:e7a0cdf618f2760ff6fdfcf4d0048120d52195a22851217f6505ff81b4182513
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:b818b560abfeb7662a05bb9873badcb843ed7e389e00c4d9f37f716a6af19b52
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:5972091bef8a99f236af2a9ba44d85c2cb0fa95feb3de0775abe8e72a5a38402
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:76c27bf9b375dd3f3e939772e523383e283947cc27d85c53fab98fc2811dc9b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:725d2e4ade8b45805ea5041b0dc7815155a22569885cb8e298eb9cddb9869a90
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:18ebd73186c507f2f31b4f2f3d63f920787f812c174d4d3bf38671a263eb056d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:ca021ad2c27ec35e5d5102f02b46a75000638298d4b104a12c5baaf8fa098883
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:4f61b7f2607f7d311c7bded2eb2fcc6cb8c917b43b4c28c5c4c184c32094ecc8