Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.6-debian-fips-dev, 7.6-debian13-fips-dev, 7.6-fips-dev, 7.6.5-debian-fips-dev, 7.6.5-debian13-fips-dev, 7.6.5-fips-dev

Index digest:

sha256:04f5bbfccbade6921b845d2b518ea991a9612bfd492e81200cbb2ef9e0789159

Manifest digest:

sha256:6f2501b4371a137876687e707c9f840774c8ec9cc0ba667915300e74a86b58d9

Size

78.22 MB

Last pushed

19 hours ago

Vulnerabilities

0
2
6
4
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:39fa70ae4578c1b3c7e1f9de24db73ebfea1ee80d7779ed8d10135cf0d3c7460
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:bd79aa067cf7449fe0629a50d7b68926939950c7f751c8516dcd690c0596e05f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:1bc94f26c94c91839640d29a85639d5d6031cbc24259687dac6943fab1366842
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:96c6ad77086a871f7e2ea405e7de873922672bf451af7a84fec27ea2bc562041
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:4d2e4aacb7048236a5c820b31c26f92d8fd6a69b6aa8628933c6cf6e7145fb2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:1d9f28b3649babf7dd04234d1d8598558a0d11ef4a27d35399df61e343cd6d0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:464606f5c24e5d3fd48a43f82da14452085ada3f9772fe64deb148be9b893fee
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:64a1fab2bf7a64ebf0954aed1edbdd0a5ef508efb487209b19d6892337a12c56
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:d735fb3d8ab5f1ded11e25f1f21641193a8d6fc57202e66333e5ebb31854f4d1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:e17c2be5098d2fdfac587e68872646cf89155e42451c84f4243fd1ef263b40af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:e0554cb0e44503f672f2d91588f3075789b3ab2171db3e88fe324da1da880ef4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:0f9877377e2eef0da9b242e7e5132bdb01928d6c41bcd774726a9e896eee78ae
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:91b5501fd7832c1742a787be4e26057551a67958d584f956a69ef332b34b2ada
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:d3c612f86ac98587628c259b048607a6c0b7cacdd2abda31dab07e1f9c8722f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:7836a65f2e0d7df81c51119ba444f9963a653cd17a3a5fdb5bb2104a1f3e2b21
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:ba6301a80327c6950babd5655314821570fe3211b38494170fb36c32928d36c7
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:8ace51345ab4909cbb23198b9f6d9821546279ef24554395696fad4c0fcf8207