dhi.io/build
2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.1-debian13, 2.25.1-helm3
sha256:2ff65b375368751ecfe6034e1876b48c99dca80fbc104da4970a5bec52ea04dc
Manifest digest:sha256:7521e9c4fc36d5a9839e4f687c849ca058ee07e9178a977d34d2d4c1bf7c9526
Size
111.67 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/build:2-debian132. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/build@sha256:6a0606e8d5eb1e8960a664808e86a510d81b88dd108514ede1a8ad37be9c817c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/build@sha256:75711af2ec6de3ecddacecc4d295e2fa6c8687d9ed6af987604a4891b365b625 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/build@sha256:c5aa1cc10d11d82e21520a699c1eea808721a42897b8364aaae2be202dce1c3c |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/build@sha256:0fa8de02df07dd1bd9d68025591daa7c9b1532e252b4dddfbd570d4f635439b3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/build@sha256:e6db1338f54ed1f20c0777d144d0e080c6506e4a0180c82e66086d32c5c93898 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/build@sha256:73734ab7b0228045c956a36ce8f5c6ec1e4b09fa7868b8306b8ea5eeccd51682 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/build@sha256:81565826601016a1c04ec9d681362ebdcecc154c8f40d6ab54011648b9fed597 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/build@sha256:79f7e7dd389f683cbaca0c37169c49ac73e564ad72ca3525a9733b4d581b7653 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/build@sha256:ee7b3e10c7b66413efcbee89effe682128da74a6a779637c19676934cc6f3c3c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/build@sha256:bebb98aae705307850fbab73972fe176b501bc419769af8d8950c4c0acb98832 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/build@sha256:70f8463218b4a458b8dc98c056d8a44b3197cfb03f67ce984d2a61a08dc2c371 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/build@sha256:8c337dc2ccfc18033d3792f55dc48024fd22fcf7c168d9845125655e16d2846e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/build@sha256:c9ae7f74a3c90e2c7c0c2b1b5fadc5f22e923e2dcb657438476127401c9397e1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/build@sha256:ab4e5f8bced14b028003a84ddf1b782d7c2473e4508753c3734bb52c9d5101c4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/build@sha256:62ebedcd56d35e9889df6ea469fc1ffccfee1b18c0f64dd777a006a5b27db8d3 |