Sign inSign up
DHI Build

dhi.io/build

DHI Build 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.2-debian13, 2.25.2-helm3

Index digest:

sha256:5a4721a7b47f01fa70bed2a0f96990a8955a705b15c706961118423171ada5af

Manifest digest:

sha256:4be7358171b77f9b8821f72136fb0de5898e24d9a21351a2f40e95615ef4979a

Size

111.67 MB

Last pushed

4 hours ago

Vulnerabilities

1
2
0
92
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-debian13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:d961af659ada26825b4d9fc0db9aec64b962c3abbd8e99eb5284dd03b8a3a7f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:04e9d6a434873566e448715497d9490690c8110499aa652ea8c3a61f6e1323e0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:02994a368082db182e295689a2697d15ab145550c6d35f396a2996d9e73dbc45
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:edf45eccafcd923f0fc5e97f3f550e3093426457a88bbe78797e91d62c9b2ead
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:9637e836db847e05bf7b0b2a71b27f598f2c810b174c6fc8957980128bf8c0eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:7d097b3c11da05bf1ad045572df1edebfef75aa2e1e6f887d43741c6f72786c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:881d704edbd0758174fc5e247c717e6619f5dfc24bb56b4058f6399fae20b75e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:e36650ae3758a2d5eed6614081eb5cf2623ae8be9b1d085f2a5a2c1a56191e6e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:d8ed9aa8bfaa071ab0915d9cbf2895719cfccb7924fd5026faf2da4f6bc324e5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:5d1c9e29e79073cb7a69378a374869feaecb6052cbad1f45e695cc6ecc3f70b4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:a61b458598ffde918901ed75b1f48197319615b3f5ca305a70ea364182ac658c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:eb058238c8e2513ee2d398984c04f3832b383ec73880cc72e76c08d9fefdae10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:3b982c9170e07c9c2b0f3c5d020751f9967a05e227d45e7a4a70f86d79292a1e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:0f24f3a406f06f534825472cc55790297415b3a714739ee3be06b7c4ef8dacbe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:e3eb167d7c6225c9a3dee3d422282a5b9347bdbdc9b478bbffc0126cab70367f