dhi.io/unleash
7-debian-fips, 7-debian13-fips, 7-fips, 7.6-debian-fips, 7.6-debian13-fips, 7.6-fips, 7.6.5-debian-fips, 7.6.5-debian13-fips, 7.6.5-fips
sha256:225bc18ed8121264f7bec4e9981927ee81a91ce2e4b4bf1fb37995bdc3c02485
Manifest digest:sha256:a2f5f6e12561cc967b27fd266bc50d25105b706b07061d1fb6dfe6f54fc78495
Size
59.56 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/unleash:7-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/unleash:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/unleash@sha256:0a0b627a54d73ccc381bd6d740ab0e0d6665534c97bf39e7ce207102bfe27b72 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/unleash@sha256:d774b466b6a762797d640a49dedcbf33e9f5846c568214dd677babb7c0e96bc7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/unleash@sha256:b97a1c16e0bc9b887c9a05c432967df90f434958a39c8525368ed5633a4f780b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/unleash@sha256:0b950ac7cbafeaab21d9bcfbcf09b73df13b1006bbe6d094c5b3d87da8eee3b1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/unleash@sha256:3fedb03278fcf53b34f63d36f01ca72f92c4d4719675dfdf26b24ea71decd387 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/unleash@sha256:d176651efd97300bf1527c566b85f7138f3c8e767847b36ea0be7904b05e53d2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/unleash@sha256:faa01b72804cea484ec082c6f756a9f2a1a3a0477e2021fc7bf72fc758f2a88a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/unleash@sha256:c0492bb81461779b09c433dd8ecf7bc4d6314fbc0a3259f6fb4f73652bf4ab2b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/unleash@sha256:7e489eda18a67b955aea98e7d6a481114444a4f1c2030e0cd6f5ac03208c9a35 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/unleash@sha256:074e106ae162e46c7bc2bf309543bdbe9dec7fc1d781acfc770ed5dcd597406b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/unleash@sha256:f59312756d08dbcf3c92948ae9a49122eab75b0741f4ff1520fe664f984c5c9f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/unleash@sha256:584050dc4898f9350321ec6fd61200fb959223bf5c5ae3c96df7f194eabeb7bd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/unleash@sha256:951e7bb9526fbdda5279cec7adb9e48905e2dfadc4e29d7fddb1ba47b3231596 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/unleash@sha256:502e658a2bd617c55a6b147c4de37b32cc1e6a6cdb15ee635c14ab3af9fadb5f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/unleash@sha256:e57194cd5aaaa6a326e2a121d8d1c058ff885c3e01516815a169e69a58f9e86b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/unleash@sha256:85b64c414d73e2762c6945acc1cf58c431ba558ce38b3a18dd3e766946522f66 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/unleash@sha256:51b4ea0af438b0d4d7a13c257cc5f219eb57219ea2e08ec7c1851cbe000ed8d2 |