dhi.io/notation
1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.2-debian-fips, 1.3.2-debian13-fips, 1.3.2-fips
sha256:a768aa66a21d8c5f4e96241f1da9ab98189293059a522f732c35e3d489461f98
Manifest digest:sha256:987596f0472955534190189fdae8f6d0ff8aba1b0509190df4ce5edba4807c58
Size
12.23 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:81526a0228aea460dfde518e70e2e7ae84cdf5646c10cd242517912b69feb529 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:32b9b6ab8fbdb61596843cd251da8adfb196af3c16280ce34994ab780eff177e |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:9e5d41b4ad53e90dab8c5afaddb04937339e766b605d28187fcf012706f4fdb1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:796ff74a4bb3fc1bdac9ee373ab35a9a4876583c1d4c902aeda2d3541a4f4cbb |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:9cf2e60d28aba3f36b378bf21e7db46d0f852bfc4ccd7bfe7823048f346b1410 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:58ca18c6942123b8d7ebab5864dad981ab50f788dd1c20a5141f0c0687515d47 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:21a0244d8c140e41fb675519d113ad0c80b99b625e968ba12d52675ac4795f8a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:44591b8453090307b182cb2154a1b8a6734d38434067c88f496b504c7e231a0f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:db2118b448920d2a5f384473ff36c48b8623b05e32797bbcd441e5cbedf36d4c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:493adcc44cb420211ae7fc54d449bb72cc249fa7254f939c5a81cc2d829bf686 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:cbb6e329ec53c171c7874f41026f4716b2061704950d5a1f67476c3ec44dd740 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:99bee81f0dd0361f297b2f03953c014e429101b7c1a0fc52cc439c0a17cc5ea1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:607a8eb142734b3ac30547fbf82b9c673e276b4650794dbb97ee311fbef7ed99 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:edf9a58ad04947ea1b7aef25ac2cbc45422279db15f67220156b5ed696fb1646 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:f199148a0387663933205f1b7cc461822ea7b5889b061b76b72b9becc96ddc77 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:4c5b7b1f83f966096c58cc46896c4c72d224b7cd2335bbd1fbeedd364da8583f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:ed592f56eb054cc001f11fc0142afc61cb424cd0fc4e1c7826a2850f5f2a45d2 |