Sign inSign up
Cosign

dhi.io/cosign

Cosign 2.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.6-debian-dev, 2.6-debian13-dev, 2.6-dev, 2.6.5-debian-dev, 2.6.5-debian13-dev, 2.6.5-dev

Index digest:

sha256:1717dec46c13896f562aa89eda1263c24b133bfa2abaa94b6423afe4329b76d3

Manifest digest:

sha256:348b3cbf904190d8241382fc717e103cad2fc167d6dfc0696e6bbc2e44213c19

Size

71.62 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/cosign:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/cosign:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/cosign@sha256:9bd83f54b565149c244083970673aa05b9a416349bb640282da4f0e456c55872
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/cosign@sha256:3919881c2aad97e257f31b2fafe1eeb08a23ad9f6123eecb7676738d60862574
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/cosign@sha256:b1d08e3e686d668ba88f9c5b9b8bbaa590fc84071eba174aa975d22973b08b1d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/cosign@sha256:16738d9289536e73581e71829afc59564fba4deb4dbaaabac709e5a72eb4ef71
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/cosign@sha256:4e0bf1cb23d120f1b6843aaf1ea62a8021e57eb1cab7ed3add2066003d66dc9a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/cosign@sha256:1ecfcfdbcff17791e3c7fbce9717b0212ed97146ea12532fdc67c598e6b6b44f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/cosign@sha256:2cd53187f131e62d98c293f47c48cdab7d04b8a558c5b21c7420123b76828b87
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/cosign@sha256:9e5006032c2958393fd9221e3dc1a8202f57f48391ba6c88f120953fdace2210
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/cosign@sha256:dff3d8d899cdb8da5bd30ec304aa95bf22aa9433d3dedd50dad99a6b5b95c996
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/cosign@sha256:39f16e005adffa62be454872e23a5bda056d8770a9fdcffc5e57fa55ef4b2971
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/cosign@sha256:e7764494f1fd9c435cfaa072c8bd4640e09cb5f07d5da1110888741fc688202b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/cosign@sha256:3eb002f40ab9e483a3d56ec34d969878949a95830dc34c547618fa0f7ae0e817
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/cosign@sha256:01ab95a326c3883585431aa4a028abd8df0636895c91daae3132c35ddefe8013
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/cosign@sha256:63252735a19c3fda3f09b49b2dd562409bfce48be0dbcec68eaedb387f14d412
SPDX SBOMhttps://spdx.dev/Documentdhi.io/cosign@sha256:09c2db385732137f1854bb4ba81494502faff41223e3390d2d8d5513d169cb0c