Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips-dev, 29-debian-cli-fips-dev, 29-debian13-cli-fips-dev, 29.8-cli-fips-dev, 29.8-debian-cli-fips-dev, 29.8-debian13-cli-fips-dev, 29.8.0-cli-fips-dev, 29.8.0-debian-cli-fips-dev, 29.8.0-debian13-cli-fips-dev

Index digest:

sha256:d48c44c4326dee9387f8f54f828bad7d356254473850cef661ebfae308b2264d

Manifest digest:

sha256:adb3ac281d4665dab45af3936c4249c4f9752a0a22ccb6170c3f3234a18090fc

Size

186.42 MB

Last pushed

17 days ago

Vulnerabilities

1
5
3
4
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:9df3adef5761cae0fbde34095c96a9d159acccf618aebe6cd44ff83206d5d4e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:1247ad00e78220d26da210a47e617128c0b009a901eefa16875725b2197e97d4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:70d8e8eabaac57fbe95036a186f9bd5c964f11560c07e5707dd95876020124bb
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:c8f31bc75b30231321fb1585f26d3bf1d7f0488ff3bf5b2790b9f7297e6bffed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:0771346cfb290e77bfb849e3a959e16658c355fd06dd74058a1695a22e7f8701
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:7e80978747849f4effa84cbf319beabdee411e5bb5089d7b7dbfe5b146c59bf4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:e577346c83b48bd112f59d2502d52bbf428b8a93d6b9697b03e39e7932bbfcf8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:651ca36748c604c6352a570f1c09af1a578db65667c5988819f5a74bd9c998b9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:14600cb799dbb41433875e9253868d0b57f3bfedb03ac467217369bb89c4d908
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:3a8051a6df24ce5c9c1e6b2d148b85e57c5035447a25cb8a13250f5c66ae3478
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:421024c9809cfcd3c42abed53f99662546cf62effcb7218ccbe05dc6010649f3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:c706b0e8cc0fe973685fc3829aac541db1148f8ffc51e3fcd97df9d19fd41758
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:2bae36c2aed9f6a413e977cf71bdb24b3921b534f3482048aeb9d9b9fce5d327
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:17592c16175058c6740f87219e75f8f94f0ccf8144a18a41d1a3fae7a42c49ee
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:e88b99196ff2aa62c8530be9f81cb446c896c418ccc82fd827f0a7bb23d513bb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:0f88c2feddc1e7444e528ce13e964c7c36d8a2c130cbbdaa8e5f1596367c2449
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:d9c00089eefe8e0b1ca7a21aa841c7a1e3da0c8661083df792692a52a3c6973f