Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips, trixie-fips

Index digest:

sha256:575ba403366bc3801c2876dac4f7d8bd2a06e16299143fbfc24a70ab9d49ad81

Manifest digest:

sha256:bf2c02ad87b721ab71ac9a796d78c8189e2b19c05910401d10a7ade3bc5b27e3

Size

13.37 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:859e609fb2477bde93613d75150d355bc2eb5953de0895d5eb71b79cb8865fd2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:0110227f11aa317d40c89676f904c742c4b228a0dfc21d0c1ead2729095166c4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:3d69c71cd248b761ba6c8056b9739e8a28c68be03201f111481934a155acb7e9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:8b33ebb3ca8557318fc264eed4b6a2fc223561f41ba0ce854bd74b49f6a99d3a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:e3d34cf7436b95f2cb71a17f2355064ee23b592b785bc28ca9e19a85259de974
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:e7ae64704447bd12ff654d072f944d4a20df2d5e3628e57aeed54f9187f0e09e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:b52dd5ef4992683e57a0ebf593ea57630a25528c8b4e724ba85c06bf925162a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:6b40c49b03131fa9e61c90abe1481f880f64b91e7a95cc3897e3d7c53c85a254
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:1c7ed9a699382cb80c0753b3981d50b8562d819e7c778c1c99eb622b9c29abdd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:002692765999db8fdf685d68625095cb989861b1f75a1c7d321621b9ebe8e372
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:0643c6ee6cb56def3ecc374e003536853f5da1275b63dbee1cf7e4cd8011a977
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:68565fbd959599709990462c6b124d8ab84a25756a0cdf7ee1b69e7abf21a23f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:8749a8ed45bc5b983531eea2d78148f81015c39fb23417df41da812750368f5a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:fa2ca8732d9e57f86d63f6a5d5f62073fc372647a06d74d7f0bc635d2fb50a1a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:6039b256f8a7667b2e37bdbf8435fedda26f7d3a08f6cc0ec54b25ea07065e58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:acb6576cb8d1882c04d99f246137b9c35bdb886be5f4338b38cbbb2391018376
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:9752a854f72363fa983c6e304974e9db297e4479f7084a6adf5d783f9c2ad2a6