Sign inSign up
Static

dhi.io/static

Static (Debian, with glibc)

CIS
linux/amd64
debian 13
Tags:

20250419-glibc, 20250419-glibc-debian, 20250419-glibc-debian13

Index digest:

sha256:5065c23b431a823160fd35e1b59fc38f97d8f11bf89d347d2ae95f3c84acd87a

Manifest digest:

sha256:80cd5605987f1f367051f84ec808a22396c18578b65344802469330b2c4935e7

Size

3.92 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20250419-glibc

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20250419-glibc --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:f73bf908030b3e23a24f5aaced620d0dce32dffb8cc229fe0f87fc1dd5aa2669
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/static@sha256:70aa3e9eeaa542f8597ce15a1efc57acd0b0676edbe06b3659a860e85d148a81
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:fa92570ce12973230fb9cbd59863484933e6003279d92d5c232a730c1be19d14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:7a1f5179f954fd6c3f80383102a9668818d3bb3d45b832bbdc59ea6c30124ec7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/static@sha256:5aefbba9fe3f5569477b94f37dcdab9f2fe5aab2c6eac53fed74849a43ea3e7d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:7d7d5bd5344a937effe8dc081d3692a152371657a6eb234dac607fad96e6102f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:8f6185ac24fe5cadd752041f0692aea67b41a34ff438e0e2ca55d93978135f94
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:443ba5ac9b0d1f72c3c5fba35243d7e94c363d7216dbf30b5f7c5d9aca0cff1e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:19952f035ea1bddaee090081144445e4c829d5d37c3a30b0f412f3761bf4deed
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:6d784ef428487ae1c7b8c5e12ca0c11df852ca27a4d0c695942638cc480a1b15
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:b2be045c272d427c109474aefc09f8a8a793be4372490ee10b2195adf3c962e6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:8f47ebae7325ae14815f3755c897c8c60e662840ddcc106b7a3260482668efaa
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:1735453101ef74f2da81bbe439c3e88b77a06fed0271d5060d0845d478b694e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:9cb053ce2f444636fd19766c1e426dc5dc6e1c613f75e2a9aa85a5dfe0e4596d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:8beb2f7f06147d141fbc550a5d219e69d75a15006b56c7fb563ddb71db62123e