Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips, trixie-fips

Index digest:

sha256:5aded52b05a424b39155709093244439df87e3ee01243cf97dfca8f02d78a410

Manifest digest:

sha256:70bb221b9c2a6297ece923a200ec8b926e3f4fcced0ef8ee4c107e1cf2d8f134

Size

13.37 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:200140258f97b464cf2adda58a9884db55aaca911b87e5bb4226a80111cd0d1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:044f878f60579d8f551e20a662f3c4f381a22ea6cb4221f34f03f18888d04252
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:4ef95a78f6e607ee49403e9230e4bdb947261ebef01d6250624438455409cc77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:d4080ee06c5f46374832448fd48d40cb2ad221e84fa161205b4ccebc5e51bc2d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:616d43b36202b3b56f68bed67635b7b1286200f4dad5504999d528db82525365
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:324b4bff4ef1066f6e8ac18df2c4c9b66de0f0172a1550cca1a6d36ebd3aab8b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:eb4a4a6db6cafdc4deeb5a68a3f75a9d5fc6d14422eb21b414d667f3264a4513
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:df55b8f823d6200838e62a55f1dc17f608d50c808d77b1d53a492880e7d0e34b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:18c9e4f39ed4e15253c9a528485add274609eb4356b46ff48106a00d15704e77
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:cbba674e9737a63082f33fc4d2c006bf92fbb98f5f82e4f1445ce4f3a66c690e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:65fa31cdba103fc987e7db6e764e08f3ffb215aec1b6c3030f823a5507e6f997
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:5629deaf9c3c1d9acbf14bbdf21751b8101d8b9c26e7d6076a39239312818bf2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:072fae0a5f03ad540ff396504705e6b84cf993e6407aac1b26721fbddd368a41
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:91d85f5522b61ddba3e9f6cdc9ba7bc06cf5af162543846dcb99e8d3cd54fd82
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:43f72c045ca8f2fccee6ba7f7fa940ebf180ee47b6154855ad9e0508c2b84953
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:29db24a71ae16696398c4719ddd3958622bf601268703cee144dfb5ecf57ad80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:78fba95f0ca1dfe9ad246fa9d6e9b9e6f6dfc9703af47684e8b4f31c678b1454