dhi.io/notation
1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.2-debian-fips, 1.3.2-debian13-fips, 1.3.2-fips
sha256:a768aa66a21d8c5f4e96241f1da9ab98189293059a522f732c35e3d489461f98
Manifest digest:sha256:987596f0472955534190189fdae8f6d0ff8aba1b0509190df4ce5edba4807c58
Size
12.23 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:81526a0228aea460dfde518e70e2e7ae84cdf5646c10cd242517912b69feb529 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:32b9b6ab8fbdb61596843cd251da8adfb196af3c16280ce34994ab780eff177e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:9e5d41b4ad53e90dab8c5afaddb04937339e766b605d28187fcf012706f4fdb1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:796ff74a4bb3fc1bdac9ee373ab35a9a4876583c1d4c902aeda2d3541a4f4cbb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:9cf2e60d28aba3f36b378bf21e7db46d0f852bfc4ccd7bfe7823048f346b1410 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:d35d6077a1d4964bcf13e66f572748a1595926afbd49b55c8b0d7ed9dc66cdb7 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:d8d8c1561d7a97a936dcc3e58382029705730ad378c0e3c9e5c1acd53ca85564 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:44591b8453090307b182cb2154a1b8a6734d38434067c88f496b504c7e231a0f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:db2118b448920d2a5f384473ff36c48b8623b05e32797bbcd441e5cbedf36d4c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:493adcc44cb420211ae7fc54d449bb72cc249fa7254f939c5a81cc2d829bf686 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:cbb6e329ec53c171c7874f41026f4716b2061704950d5a1f67476c3ec44dd740 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:99bee81f0dd0361f297b2f03953c014e429101b7c1a0fc52cc439c0a17cc5ea1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:5a4b3be9d47eb6ccc85b11348c138a785815b19ba027292cb54eff3334bc0fac |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:edf9a58ad04947ea1b7aef25ac2cbc45422279db15f67220156b5ed696fb1646 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:f199148a0387663933205f1b7cc461822ea7b5889b061b76b72b9becc96ddc77 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:4c5b7b1f83f966096c58cc46896c4c72d224b7cd2335bbd1fbeedd364da8583f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:ed592f56eb054cc001f11fc0142afc61cb424cd0fc4e1c7826a2850f5f2a45d2 |