dhi.io/build
2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.2-debian13, 2.25.2-helm3
sha256:f941e8e7df9f965e68d933b9d4054b6f8cc7a9ab08ee58a0e98dd16061c8e2f7
Manifest digest:sha256:2ab366492ec5551c508b6885a4f956d52103c5579089f417e6bbc1603cde54d1
Size
111.67 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-debian132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:bc92506b7104da10c26dae7dcbe69e79c4f6b237f5cddc51965dd57f23e2425c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:c1e045c628568449d3111c6f5d769c79978a41e909584861ca8c58a775c6ddce |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:988300fccf0c69e772d770869c57469fe1784641b112c73f53cbc7550e7bb6e2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:4288074034b917334ba0ac8ae477353d21906a8f01fdd51433cd18000141475a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:96c9511e0bd5dba96c7f386a35f807e70c838c33f33cf1fa7738f25499bd0325 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:dc119f26fe2b0ed71485a49d72ab67a73bb63c94ac27cd42b60b079636c226e4 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:066468028a492ab05f9e1ef08355ee7975738c02839018bd95b59e822094a839 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:4a5bcc1b11957795c61de85aa445662eeeb2c5965ac1863d1742248d44fb2841 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:f459436c7aae6e86b7d5fa72882a5902e254c9010dc61f189d095bee1bd8eb33 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:42a4d3bfd32558dd2eb24e8a63010bad38a992532e32d5fa017bc782f5d8f7b5 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:fa2650e6a247511032b31d9ab02c7064c6282f8ee8346e4a5f9335cf9c66a7d1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:056b0f59ae667fda520e6ec7ba4a2a6a37b0216b77ce7af9625c3885723f0143 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:28130f8b0174d4b46206c3d734d004f566156b49a6e10c69c2d18f6a391a8fc0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:9ba629faca5539ac74dcdbce65409a751126d2abe0a34d64e8e17c6da2eccf93 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:c1044b62d0e26200c18cfd11023c38ef96652ee6fadfce0f148f46af36753ea5 |