Sign inSign up
Dart

dhi.io/dart

Dart 3.x (dev)

CIS
linux/amd64
debian 13
Tags:

3-debian-dev, 3-debian13-dev, 3-dev, 3.13-debian-dev, 3.13-debian13-dev, 3.13-dev, 3.13.5-debian-dev, 3.13.5-debian13-dev, 3.13.5-dev

Index digest:

sha256:d640e82bd0bd85bd39476f668134d9e778032a5b99205b953597c5fe65ab7fd7

Manifest digest:

sha256:9eaf1473741017ecf7228fd04ad593836f242f715aeac8671a9ef92f19b0357f

Size

217.09 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dart:3-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dart:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dart@sha256:b2b4e7c777b8d85af966f68dabb9bdd0ffea96a282577247524181d086c8e996
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dart@sha256:917904f6e590ec741d8a2c09d674818d7c932168141fba4db2da7e65a22738ac
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dart@sha256:093e7cf96ebc8305acb33b4fe0dfd4daab3072472f0cd2727ec4a134d953a544
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dart@sha256:1e14769a7152aae275070db376d0e3d952329f9f4d549a697808022132c6cb9b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dart@sha256:695fe434ef45252b945d7bc0772e5594bf17b0e28ac877386f737a98b4b6d8a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dart@sha256:6b2f562ca3a17526a661b7ce8f99e8014e97c957df0cb762b74e1bdb6cbddc35
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dart@sha256:8ed0aef8ef1a62e524d762d0400e304e7373c05a58336a7eea751336514324b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dart@sha256:92a63d6bb05dfa6a5657c426326ffa2d9bcec833874f071214f05369dbdd2e35
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dart@sha256:994b86dc464151f2aae5bbea7040c339b90995cb1ac0ed1ffaaf5b3f49cdd202
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dart@sha256:e8dc9231d6cf2b3ca70bb77daee0dc4a52aea7c4558d2d8f0a01d7f77576d1f0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dart@sha256:1e11f22a216b1c6a733f61db528ccde4ec0c5f32bb1b33cc2a6581c103be18e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dart@sha256:23edaa8ba9a013ba535e3cd157ed8f2674bccc39e9e1e57ef526d8a779d5b840
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dart@sha256:fe2e36bd06a7380319d26db309442d1f755baa7f000ca73cb9693ac902fcad9d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dart@sha256:f2626ab6725e855d29344f6be61c4dd927851cc970faaa2c304986c364d66648
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dart@sha256:146c438b10fb33ae5d908c2b036defedcce7b50add8bff43ff8f5cb8a9a7c916