Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, dev)

CIS
linux/amd64
debian 13
Tags:

29-cli-dev, 29-debian-cli-dev, 29-debian13-cli-dev, 29.8-cli-dev, 29.8-debian-cli-dev, 29.8-debian13-cli-dev, 29.8.0-cli-dev, 29.8.0-debian-cli-dev, 29.8.0-debian13-cli-dev

Index digest:

sha256:d5570a4bab6149d3dfcb34705458ff908dd56159db24ac7804c9403b819c381c

Manifest digest:

sha256:31056c9054205649a5e791b596a579bb153257e7658626d584d5f190e11efb96

Size

185.70 MB

Last pushed

17 days ago

Vulnerabilities

1
5
3
4
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:6cc4a99cc197f76e12899f434ec87b43000f15061221b3b705e28d57f070262a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:39a666b2508c9cc52dec76a8aed738dd9995b4b99ef6185936c14b46bbdf56d1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:4ce30056215ef8bf0128071db66e64a6ac1c57083335b371ecb6fff183e5b5bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:7c763e637eedf1bdeb74d2451362dd0ad717bd31f1b5df8697a96dfd083b3c49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:35ba719b7590a82407df9cf4073560523374b52b49aace3f20728b537f2c84f1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:23bec00ae33f8bf1f51113932b5d81a7231e9137e6da9ae26c167a8b0e46f204
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:d83d0a5edfb1a52f67d4218a5da233f2211499d6201753bff8f50e7d8e773374
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:422cd38b8cda74a8a9d9abb55dfbe929b372d0f3ec2a125619fa6c6d425d0e22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:fc9c06396b61ba654d3d13ef48495853f9bc90cc3e435b1402918a11fab85813
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:5e83b0e0abb6c6b3a058a06da3b8f25ae4c697be3755166e9a916069b1ab20f9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:7bbe7bc8f4ebe87065f0a8c87e394f53ddfee3b72c6a7bc24e8b8159416bd1f5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:ef94586825df4186c12d989847237719e0e1ea931f017c5fea7f79f5df7779b1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:5fe17beea2c7cd62551f2ab071c605a6b59d8b3d873610a6ac207045e7f63704
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:aa21c695dd05157f6e21f666a19115f6cb3d97a5b645cd9252ffcbe38c24766d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:bd58fe2a34017ab1b60b82c1383d0d624b00d2b47ef93f5bc931924f54078bbb