dhi.io/build
2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.2-debian13, 2.25.2-helm3
sha256:07e1df7704fadd1c2a0fa7d0b3c76591e3b096a81c5827a95f96cfabaa248fc6
Manifest digest:sha256:8cf2213a569e6104cb2d70b24958ffedabc69c5dcba2cb3c6dc4f4d345fa7820
Size
111.67 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-debian132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:bda76deed05a8644109ec9d7a0e89f64deb358ce1a1ea380043220e3a0958a37 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:0de86c49159d6d6132c4b39a50a263b304a0e99c7fb0bd31fe2653336474315a |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:3bb5e6d082b88c86d6288ef8df511d5e5abcaf8322276d0b540fc2273627d1c6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:dc8a2d57196f69c5a2b05b3813f844398bbce05c5fe8c2ae13f6daa2145ea15a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:9f9a221c050bbe0b5b0cde50d4217eeb7ab191283777069b4903b1c00d0376c0 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:96460573cac07a88c0f7517e57d3efff702d227fa4f790e3f075cc6058c7053c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:77d9dfa4cd225a2aff5a403166fdea67167ba66bb21f44ef38f88b0c43ab70a0 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:304d6245cf5598430cc31d56d0544027419de4c7ec58d6e7ff9bdcb44ef7b555 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:c4bc5a039c5a5f8b92c87478e06391041adcb9a79d1bdb642920b1d6a7756332 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:790aced94e262f83be05f3fdf491bb53ccc6f1bf072f8e5d00d9e29dff6935f4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:458b1c947350346fb93cd27fc7ca04171c36de840241afd33cba6d14966602b1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:1031bd657727b12bf9ac431f808d65eed2a5fcede3348140986d820a0c663cc4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:8459c23a8f9716f33a0d82b132a47aa4c66a2f6237dbc0e2d58762eb84955ec0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:b5acb94991e955455c8e69f290b9f8d746bc003ae3fd749f904438d89afd9d9f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:f977e9a45a3d40a540c2b4ba35bba665aaa6f4e173de3d35f7658116d5e3aa33 |