dhi.io/build
2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.2-debian13, 2.25.2-helm3
sha256:5a4721a7b47f01fa70bed2a0f96990a8955a705b15c706961118423171ada5af
Manifest digest:sha256:4be7358171b77f9b8821f72136fb0de5898e24d9a21351a2f40e95615ef4979a
Size
111.67 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-debian132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:d961af659ada26825b4d9fc0db9aec64b962c3abbd8e99eb5284dd03b8a3a7f2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:04e9d6a434873566e448715497d9490690c8110499aa652ea8c3a61f6e1323e0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:02994a368082db182e295689a2697d15ab145550c6d35f396a2996d9e73dbc45 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:edf45eccafcd923f0fc5e97f3f550e3093426457a88bbe78797e91d62c9b2ead |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:9637e836db847e05bf7b0b2a71b27f598f2c810b174c6fc8957980128bf8c0eb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:7d097b3c11da05bf1ad045572df1edebfef75aa2e1e6f887d43741c6f72786c5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:881d704edbd0758174fc5e247c717e6619f5dfc24bb56b4058f6399fae20b75e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:e36650ae3758a2d5eed6614081eb5cf2623ae8be9b1d085f2a5a2c1a56191e6e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:d8ed9aa8bfaa071ab0915d9cbf2895719cfccb7924fd5026faf2da4f6bc324e5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:5d1c9e29e79073cb7a69378a374869feaecb6052cbad1f45e695cc6ecc3f70b4 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:a61b458598ffde918901ed75b1f48197319615b3f5ca305a70ea364182ac658c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:eb058238c8e2513ee2d398984c04f3832b383ec73880cc72e76c08d9fefdae10 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:3b982c9170e07c9c2b0f3c5d020751f9967a05e227d45e7a4a70f86d79292a1e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:0f24f3a406f06f534825472cc55790297415b3a714739ee3be06b7c4ef8dacbe |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:e3eb167d7c6225c9a3dee3d422282a5b9347bdbdc9b478bbffc0126cab70367f |