Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (compat)

CIS
linux/amd64
debian 13
Tags:

10-compat, 10-debian-compat, 10-debian13-compat, 10.1-compat, 10.1-debian-compat, 10.1-debian13-compat, 10.1.8-compat, 10.1.8-debian-compat, 10.1.8-debian13-compat

Index digest:

sha256:c26e8f125ffe56f07f6d887fcc8f86f49f466ae9a3c197cf4a3136d6b3da20cc

Manifest digest:

sha256:aa6056c144b5fdb7f7950e1daa2c2df0061f869c1e27c3328a63c094f08aa68a

Size

24.86 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:d62a080527d583c010135024b616a77d66bce41147583258f35b0f8378ca1417
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:927c26d80de7391e0ba97531dfcf77295fb34388da23467d54514bbbd4516c22
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:b5b344ab7964a2799a23930874f35484bc5783b6c975afeebf211a73347e94da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:ee8dfcdc2e69cc0d27024ecd52f779018bc60bf617ede934916ecc92313270e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:c879ae7cf0c7efe0247209b3770250bda463b5c0fa123a635da389bbc9f66965
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:1baa2878d97f0a63d1e61f3ef69255cca659daa8e8345d61b77353159609fba5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:36d081a48e0224da2d722cdabe350b78bf003009c6a9f89548867fa6f37f5653
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:a574b8e02b242ea5d3e18d6c0018d342e56fa6f4efd2e45b65f6b6737a3baccc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:8decdffe77dfadd299e1c8baa9506b551b4edcadf6db578cc636f7a232a96b9d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:b692d16c00985a60ac5161c9238c90d3054f8cceb9cf491d836c9055bf419aa4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:75c5bcc1cbeec4e6b49d3cc4d4b000c094b11641d90aa416657cc51e113155d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:38fb64022a373721209178079f04e3304507790d3764e3d6dfc3b526e4e13ba8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:d02d947785ba885e1f8a6e2964afe6b0a1eda404a35cbc3c3d97c7f1eae8747c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:b77811dd2cd2ddddd7f016c9623c2d94ff53ac5c4d2a8ca202cba7da3bab9fb7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:d2eff2f73ed952d5da5f501bdd5dda60ee49bb9877d22c4e59eeb99bcfa8ef7d