Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.6-debian-fips-dev, 7.6-debian13-fips-dev, 7.6-fips-dev, 7.6.5-debian-fips-dev, 7.6.5-debian13-fips-dev, 7.6.5-fips-dev

Index digest:

sha256:ed737deb63ea0aa474fdf7965c6839b53877aaa9107e6b1af8863c1893bcd26d

Manifest digest:

sha256:d9321cc922ae071a08ef1ecbafcba725beb034cf7c8bf3071e9175fd42eb72ff

Size

78.45 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:d46b0dd55025b0ed2749694aa88fb40d50abcff163a2ebd4ef1065bcef3cef21
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:d833534466f6efce889716b86ae30f41091bd7f1da917edc28ee2e5e5e726e1c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:c5dccb417d92970bc8852a14f8412925f5911d717d60641cefcc6412a55149b7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:6a27c949d11e73740bdf0d993c9357d2b2ab30541be2065aab62576b45429271
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:23f1a82aed8f0a5235c11d104d92d12e70e060a387b98b543f47ba8f4e4c4403
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:8bc5bbd6eba70051dd4e9885ef7fc9ba5d38c8eaf6b8b2d44e90404d5e2934db
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:1cc6e5c0a937f88525720609f80c2feb59ba638602c7d8ba0b1d5ea53a196051
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:1ffa4b79146a9b59089276bdc5f70390d81fce5476da644128122271373fa5bd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:8c92114f76177432849787d0d96034cd1c810cc11164703766584af5720ba7a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:b65fa9a3f338e60e7d8ee888ab3d6206c42273054819426b7481a4fcb0749b0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:b46bf41b9aa43caf38c47c0e63c37767ef45548d25e1b7560eeb120167efa027
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:183e3743600cd1a3fd28b7ed132287a95a245eaf4067fc663ea5e1399c347876
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:3512db6c2445b045c55bcf1291b658d6cf60c3fad5f8b3eb9f4631832f95bf62
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:6a6674ce7cd7fd574d256992cc733152753bade9566dd55cb76155f01a8d3ba1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:a17041e4868f4cb1628c5c5892cf82d9a98bb6ef1d3c8c0f5932b0c495709a43
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:e2895f7cd5cb2088f0cd46623b7e73cd3c8d2b53600ec39a1e210da522254791
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:ed323675676619209fb2013c872d5a2ece41a8d4ac0fa0f396d6ba0e31392d12