Sign inSign up
Docker

dhi.io/docker

Docker 29.x (cli, fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

29-cli-fips, 29-debian-cli-fips, 29-debian13-cli-fips, 29.8-cli-fips, 29.8-debian-cli-fips, 29.8-debian13-cli-fips, 29.8.1-cli-fips, 29.8.1-debian-cli-fips, 29.8.1-debian13-cli-fips

Index digest:

sha256:58ce07253317f8261493bf160a8f3ca9d3cef4b18c91b18dbb1e02631f761d5b

Manifest digest:

sha256:dcea690263640a97639812df2f610be19e3d586969df5f3bd7c150947e734145

Size

111.98 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/docker:29-cli-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/docker:29-cli-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/docker@sha256:b73b0befeaf490390b68393ef96d5eb44d924672ea90f4beb1c7d6bdf25a0a46
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/docker@sha256:fbf000cfb781e72055f3c32c0cf2bf1575fe6fbb789a1a51791e31c787d7c750
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/docker@sha256:e7234e467728d53bb0aa81f0eea130135894a3abd7a6b3d0fd7fce47a8f0457e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/docker@sha256:dd74bd4f4c8b8eb6220acd89d37fe8d02ab1170ced05effc05ab97f97fa17cea
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/docker@sha256:c735807070874b014480251faecfa8145e3fc7db2828e53bee556c16b18c358c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/docker@sha256:4f1dea0709e74d3bb95ec18ed1be5c5919b86bab30b84906c7a2f6fa4ae80812
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/docker@sha256:48a58849f95246f02c7f556ac261afea639548775a8258bdbc807c9abd9de695
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/docker@sha256:babd52d674f54ae610cacfcce9acbc50b544724ef556a245dc7f577fb0ac043c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/docker@sha256:f4793432e8323a784bba8a58471af2cd3c5f21819b58dfd4b16b40e80af2544c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/docker@sha256:ca6b08028297ae96ea2bb78f47a1eeadb8d78309ef7137d6cb72437a445331eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/docker@sha256:b71b3d27992640df168d9cb25f8d68f3d2afe6091375c70b7e6dde077643d169
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/docker@sha256:3f97a6d8b8f2cab822b95599f54646940ef70bc2401b617e7ff66194bbe5a696
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/docker@sha256:f3151371f2b1e415824809f46f3653bbe3ed0d5495b3ab151ea3994b06aa832f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/docker@sha256:ad60a8be6eb6679b6564da38e6c26dbc50500ef6fb5be67d2ae4a706f9e76dcc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/docker@sha256:a57fd67ef7f9b2bdb9921f290a419fd19c5d3213550fbe283ca273f1d8fc534c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/docker@sha256:3c2e6998e2394a424ca556bb520a00b3faca9d07632e5191dd940efcf152e8c3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/docker@sha256:416e0b3c110668bec2066a363cdb28e1e8775d25b2ffd89eaf3c4baf444b30a7