dhi.io/polaris
10-compat, 10-debian-compat, 10-debian13-compat, 10.1-compat, 10.1-debian-compat, 10.1-debian13-compat, 10.1.8-compat, 10.1.8-debian-compat, 10.1.8-debian13-compat
sha256:c26e8f125ffe56f07f6d887fcc8f86f49f466ae9a3c197cf4a3136d6b3da20cc
Manifest digest:sha256:aa6056c144b5fdb7f7950e1daa2c2df0061f869c1e27c3328a63c094f08aa68a
Size
24.86 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/polaris:10-compat2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/polaris:10-compat --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/polaris@sha256:d62a080527d583c010135024b616a77d66bce41147583258f35b0f8378ca1417 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/polaris@sha256:927c26d80de7391e0ba97531dfcf77295fb34388da23467d54514bbbd4516c22 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/polaris@sha256:b5b344ab7964a2799a23930874f35484bc5783b6c975afeebf211a73347e94da |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/polaris@sha256:5d1751de6d6e7c42874179035bac40a8a9383ce9d5bcb96cd95ab8643da958ab |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/polaris@sha256:bc3da7dab3a7f0a6887921560454a32e7fd5caf504c08a3c419574004264bfcc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/polaris@sha256:1baa2878d97f0a63d1e61f3ef69255cca659daa8e8345d61b77353159609fba5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/polaris@sha256:36d081a48e0224da2d722cdabe350b78bf003009c6a9f89548867fa6f37f5653 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/polaris@sha256:a574b8e02b242ea5d3e18d6c0018d342e56fa6f4efd2e45b65f6b6737a3baccc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/polaris@sha256:8decdffe77dfadd299e1c8baa9506b551b4edcadf6db578cc636f7a232a96b9d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/polaris@sha256:b692d16c00985a60ac5161c9238c90d3054f8cceb9cf491d836c9055bf419aa4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/polaris@sha256:9d7986c97ffd44a42d43b99e01992eccf1d50c7e75f04abf0d482603d43ffd4e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/polaris@sha256:38fb64022a373721209178079f04e3304507790d3764e3d6dfc3b526e4e13ba8 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/polaris@sha256:d02d947785ba885e1f8a6e2964afe6b0a1eda404a35cbc3c3d97c7f1eae8747c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/polaris@sha256:b77811dd2cd2ddddd7f016c9623c2d94ff53ac5c4d2a8ca202cba7da3bab9fb7 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/polaris@sha256:d2eff2f73ed952d5da5f501bdd5dda60ee49bb9877d22c4e59eeb99bcfa8ef7d |