Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.2-debian-fips, 1.3.2-debian13-fips, 1.3.2-fips

Index digest:

sha256:a768aa66a21d8c5f4e96241f1da9ab98189293059a522f732c35e3d489461f98

Manifest digest:

sha256:987596f0472955534190189fdae8f6d0ff8aba1b0509190df4ce5edba4807c58

Size

12.23 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:81526a0228aea460dfde518e70e2e7ae84cdf5646c10cd242517912b69feb529
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:32b9b6ab8fbdb61596843cd251da8adfb196af3c16280ce34994ab780eff177e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:9e5d41b4ad53e90dab8c5afaddb04937339e766b605d28187fcf012706f4fdb1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:796ff74a4bb3fc1bdac9ee373ab35a9a4876583c1d4c902aeda2d3541a4f4cbb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:9cf2e60d28aba3f36b378bf21e7db46d0f852bfc4ccd7bfe7823048f346b1410
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:58ca18c6942123b8d7ebab5864dad981ab50f788dd1c20a5141f0c0687515d47
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:21a0244d8c140e41fb675519d113ad0c80b99b625e968ba12d52675ac4795f8a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:44591b8453090307b182cb2154a1b8a6734d38434067c88f496b504c7e231a0f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:db2118b448920d2a5f384473ff36c48b8623b05e32797bbcd441e5cbedf36d4c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:493adcc44cb420211ae7fc54d449bb72cc249fa7254f939c5a81cc2d829bf686
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:cbb6e329ec53c171c7874f41026f4716b2061704950d5a1f67476c3ec44dd740
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:99bee81f0dd0361f297b2f03953c014e429101b7c1a0fc52cc439c0a17cc5ea1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:607a8eb142734b3ac30547fbf82b9c673e276b4650794dbb97ee311fbef7ed99
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:edf9a58ad04947ea1b7aef25ac2cbc45422279db15f67220156b5ed696fb1646
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:f199148a0387663933205f1b7cc461822ea7b5889b061b76b72b9becc96ddc77
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:4c5b7b1f83f966096c58cc46896c4c72d224b7cd2335bbd1fbeedd364da8583f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:ed592f56eb054cc001f11fc0142afc61cb424cd0fc4e1c7826a2850f5f2a45d2