Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:bb6608c2ccd13c0a17fb71d8aa167cc3b80a68ef3603fc36d929ab92fde7c12a

Manifest digest:

sha256:8bc6f039dfe9f3c07face5d2ea5f496046c2870b2346a1383b10aab4023668e0

Size

24.33 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
2
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:cc21e863260ad0c9d1670bde22b8d6a346a8be57dba6bb110fdb6498961b7b6f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:3ed4273a27d9f5bd42aec927fb77fe1cefc7aee123342ccaf54cef2367363cdd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:474256562d8789446af47bcb05ad6b5a18eb57fb283671d7a12ec8c47f8aa007
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:5916d17a18e14452d874d9a223a0b261dd9f1cf9d4d69f9a066cdfe6cae88b4b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:485c048b87ded27f5e5ac302fcd89cafd4c46040bbb650930fe7275fe608841d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:6f327c563db484114a2a437ca6fbbfe0aa7e0b011ce5292193ee91d962c97618
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:c9afeb217acaa03009b16d1da5d5471c6062536f83c3526f51bf9bd470a737a0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:3a93195971e06216c5963e4957487e90ffde348161cd8b128faa854101889b0f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:947d93206483ebacb8dfe30b88f9b2978c096eae92ff4ff122ecd04cdf75ec8d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:48c0eaddd50de3401914debf07e4ffc3af945963ec8d0092565ab3e6de908150
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:a067daf061a50f34cdefe1b67475c5878178445b86ad107517addbfdf462714b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:5d8c33b0f4e577d7c9fa7fa4d6c6bad1fb33ffa36024b3e0e256d5b271e49800
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:70950731896b92df1992ceddc4749a231212126e3f38aa0c53f41f28242407ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:5fff9a3644a761a00be113319262b5f9f061b7ae27a9cdd2cd3c3a8c7eae34c0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:3257f3df221ba96a1cfb76ad3742ea055b62a672b81a4561a04603ecb326f1b5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:d2d3c59f4d763ff06b9a45f5db85d0479488fb891ca629962106af7b9e267126
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:0841121703da541574f5e0d73ffaa3f389f7867318d6fdd365a76fc126220c35