Sign inSign up
Nessie

dhi.io/nessie

Nessie 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.108-debian-dev, 0.108-debian13-dev, 0.108-dev, 0.108.8-debian-dev, 0.108.8-debian13-dev, 0.108.8-dev

Index digest:

sha256:db90f27eddb888c45b67daaa8cbee1d1f617043954594b9aa41d8cd1f97a42c9

Manifest digest:

sha256:9d3cfe39311db4e97b86158c3bcd7a4e09be4888ff7fcf51b5660973ede8b767

Size

295.14 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nessie:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nessie:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nessie@sha256:240674172ca5c775e456b0dbe2f23576c99c5e77010f505e7f4b94d74a031a61
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nessie@sha256:7d9c59a2b95175163e5cc31126e2c3adf90960b5b6fdb0faa6fd0218c8c2854d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nessie@sha256:87ce556b65841a4ef34085c4d1b8163c683f0c5756f032439235594563f48ba3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nessie@sha256:0d5a9a4f42a7b6f1d79e3be98c41af1f2f24fafb8276780cb05ac654cdfc2f92
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nessie@sha256:cf50f85a4dc7cdafb5381e820c9cf8cc6bcaa940f246e4423e1263122b9945ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nessie@sha256:9406292f8778a7b66b965c2fc1987bfcbf68427b372f6442d438459a65cfd67c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nessie@sha256:5f42f39f438ed790876f30a54e076df203c70ac81a8a89c7efade7ca6244d85a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nessie@sha256:0ab8ecfcde3ad4a6575950f22bdf768f095516d9a7dec765f35a55b6a4fa1696
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nessie@sha256:d54410d49b5e40070d2b05648ca1a7ad8ba4886a8c64af6f97397b44b98a1aef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nessie@sha256:7269d9d93aaaa7fe6f20b35b5cb5d7ba4a6ca01fa34822a016b80e48afdb2770
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nessie@sha256:7505b459f624259a3e099e073060fc8dbbf819470bf55718a3f025cb0992b3f7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nessie@sha256:b8ba9f83f4722b963c20e9a35630a57aa15699bfdcc94e0f891d3e16b5950f7a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nessie@sha256:605d4bb8e802a98937b830a7638e17d4f88223a630821b0551c833177116dcb3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nessie@sha256:8200a6aeef172dd02266f2f605e1174f39b8987b69cdf6a880974780b1e03d4c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nessie@sha256:1f3a74556f0b122629dbc81d72f0290d11c996c6fae216bb23d5e8dcbacb6e56