dhi.io/polaris
10-debian-fips, 10-debian13-fips, 10-fips, 10.1-debian-fips, 10.1-debian13-fips, 10.1-fips, 10.1.8-debian-fips, 10.1.8-debian13-fips, 10.1.8-fips
sha256:600d37a83ae8a59810fe2ea285e9a8efa5cf994ca794ba814a73359d58807249
Manifest digest:sha256:6b74ac35586a67d296c96d7380fef6ca2076bf80868726f6754a0b320aae0e73
Size
20.94 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/polaris:10-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/polaris:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/polaris@sha256:92583a0b95c6ce95ff6e0a2e8a3f4d2c5a2276c3ba013f1015f85fb49c7e7363 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/polaris@sha256:2362f8049e3072399017e49ccc49648dead155dc6f5d27438785e20d8a1b1cc2 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/polaris@sha256:2c0c7f15e45d2fafdf42a4a17282d664ac44ecbc84a2a1772b264334cfa472cd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/polaris@sha256:428ce66f3fd345a9657ee19381c717f9a3baef2d68f37833d089ddd0b9eae5d3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/polaris@sha256:049e45a8d1fba246231a093858dabd4b079745c686b90ca0a2224a01d3ff77bf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/polaris@sha256:c02e2a4fc42d25a2f9ab1db1249849074e68ffb1a45774f0b86ff8f5df39c4b4 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/polaris@sha256:0896b5f7811d823d6d4e284d1ffe951925b606b5b53f623f4bdaa40c640dbf8d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/polaris@sha256:c54d782e369bab3bec7fb511c2fa49e0f3befc754f258c3ee7e559f7fb7c3cdd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/polaris@sha256:8433436ad6f78edf60efe646f65ade3f21e16b3ccc9ad02cd863704773abd070 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/polaris@sha256:c06b0551303948451e0d432b6f2e0d1bdd8f88b6859ffadfbc851f9e9efefefb |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/polaris@sha256:fdd4807f844fc67c0b05cc8baeb52b79388fdc594f7a3326df4a2b603d6e2780 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/polaris@sha256:9d983727fc497c846fd4a88236758a1ad1a3c14896f8f444fcd377280300ef68 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/polaris@sha256:9ea67037af36f97db02c3f2c3d26f6becb5d2d1b242c2f06558076160fadb421 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/polaris@sha256:42c35623cefdf1b285ea3a8bc61c9b33460c9643389dbe1921b03b2f29610063 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/polaris@sha256:bcde1835a42e5ddf360d6c7b674afbe509432999e5e25d8d78a7896ccd14dce0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/polaris@sha256:9e231b92a1b1a04ab5c40e34b60144646b1868a1798b0f3b81e7f2fe733a10ff |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/polaris@sha256:e237d399d7fb68e5549ed1c52df0d0b453371b6e8ca1e93ee3cd8ecdda7a6f8c |