Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips, trixie-fips

Index digest:

sha256:5d35a6ed760f708e866e4835bec29d59a5c75a3c267273da84414fd3304de10f

Manifest digest:

sha256:0c70852699444ad10b0654c9768ef6f0f6671472e2fc5e16b6e1d8ef0a40101a

Size

13.37 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:a5f2d65302ab7f655a954a01b3d52c094cc689d230b1ec496a154b023641b4a6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:cacb0582ac659b524ca5741685fe75c110cae4eb0121cd347e5299d52cd2913e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:6c3f85a6a443337e021068ede0c21ef045a85d1603d73523d2c8ae40920573d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:4c58cea8cca7e41c686e7b947c071730f3715cbf36a120580f739766752675f0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:56f2e66c5031ec8042823b328a5b6f6977bd09aec8fd721377676cdf4f407684
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:88665a1318b9b02a8ae55d599d8d5448b0662eeabb54233d645fa3e50f205f7b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:e88d9d0ed97b4cb0a1c6e6eeeb1680a3e0648132ad04be3a70b61ae112429a40
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:be97147166dbceddcff691f49394625298f5aaa0b0c1291293673e6a40ddd191
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:46334e951eab409045060843a4745ec9ca72d28c4b0c4427f810b408511d1ef4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:d8c228fe8c23f65e20d5a013f7176410ed18cd2b136a5924ac807e0d1acce78a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:beddc9e81fd535ab226bf0b56430b734687d8cf0f38f02af569948ec5425bf1f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:1ae02ba9197353043a8bb08c238a2f9acf63ececf06942c130711dd053098ef3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:82833461cde29005f9d4342cb8d35beb99d5b9c46b7b86ee5ffb5be1b229e390
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:6fbcb14642b166d21f2f09e55d16e6a9f4d07bb4e5aa3b266b8f269bb4cab64b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:a98a8cd9d3ec7a14751004dea24e9a59c7a5169ab9e0d9d913878e477b087067
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:b6ce0f0fa19a4e39468d6956adadcaa2d21fcebae50a2c4d76a5dffed4b088b5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:560766b75293b00b29b0a313ffc83b3ee4646a272a49313674333e522084b90e