Sign inSign up
DHI Build

dhi.io/build

DHI Build 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian13, 2-helm3, 2.25-debian13, 2.25-helm3, 2.25.1-debian13, 2.25.1-helm3

Index digest:

sha256:2ff65b375368751ecfe6034e1876b48c99dca80fbc104da4970a5bec52ea04dc

Manifest digest:

sha256:7521e9c4fc36d5a9839e4f687c849ca058ee07e9178a977d34d2d4c1bf7c9526

Size

111.67 MB

Last pushed

2 hours ago

Vulnerabilities

1
2
0
92
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/build:2-debian13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/build:2-debian13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/build@sha256:6a0606e8d5eb1e8960a664808e86a510d81b88dd108514ede1a8ad37be9c817c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/build@sha256:75711af2ec6de3ecddacecc4d295e2fa6c8687d9ed6af987604a4891b365b625
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/build@sha256:c5aa1cc10d11d82e21520a699c1eea808721a42897b8364aaae2be202dce1c3c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/build@sha256:0fa8de02df07dd1bd9d68025591daa7c9b1532e252b4dddfbd570d4f635439b3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/build@sha256:e6db1338f54ed1f20c0777d144d0e080c6506e4a0180c82e66086d32c5c93898
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/build@sha256:73734ab7b0228045c956a36ce8f5c6ec1e4b09fa7868b8306b8ea5eeccd51682
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/build@sha256:81565826601016a1c04ec9d681362ebdcecc154c8f40d6ab54011648b9fed597
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/build@sha256:79f7e7dd389f683cbaca0c37169c49ac73e564ad72ca3525a9733b4d581b7653
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/build@sha256:ee7b3e10c7b66413efcbee89effe682128da74a6a779637c19676934cc6f3c3c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/build@sha256:bebb98aae705307850fbab73972fe176b501bc419769af8d8950c4c0acb98832
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/build@sha256:70f8463218b4a458b8dc98c056d8a44b3197cfb03f67ce984d2a61a08dc2c371
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/build@sha256:8c337dc2ccfc18033d3792f55dc48024fd22fcf7c168d9845125655e16d2846e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/build@sha256:c9ae7f74a3c90e2c7c0c2b1b5fadc5f22e923e2dcb657438476127401c9397e1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/build@sha256:ab4e5f8bced14b028003a84ddf1b782d7c2473e4508753c3734bb52c9d5101c4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/build@sha256:62ebedcd56d35e9889df6ea469fc1ffccfee1b18c0f64dd777a006a5b27db8d3