Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:4ee34308de2c7a62947a6e6a8873a26bbab6638d164449be8be4b494f908dbcb

Manifest digest:

sha256:e5ef806d6480857f2b165243cb31005c20052cff580b2bdb828704c91d9f2ccd

Size

23.58 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:987d48abad585ad1dd527b8799f29bc631aa572784eb7edbbcfac4f839e8d869
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:4b5d7b4b77931d1439fc8dd20c41e84360ec02941035a0da8e3fc7b11f3446cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:40fbc5e547c9327769bab6887b7e09f2174395792cd706a7616377841b3ed9d0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:26531c1a9d6db5c380d3a9d6f00c138fe67cc61ebf5d577d65d3ba7b4be43985
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:c7551234ef27d717cdc32d221df7d151102406c51362d0e8e16ffba488b743bb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:de8d7c63e2ccc110cc2391efe8cf80d950896d5cffdf9e517cc35cdab6ffc8e5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:b73dc68b696f4f999f097de28ef7b5c40852e03880c6948285e345a0a832e028
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:4cb2f88ad35d967c9ef08e47da74afb2b291222f4e262c32086d7fd07acc8fc2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:19d2b4aaf36d3aff4944a3fb2881c0189533960efa7048885c2f3bddadc45c7c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:60d3cbc53157ef3e915d2035c30da101dfcd69ef8eca34406b25ec944f19bc6d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:70559a883ced3acf96d63a8f34cc8561bc98bcd7393e07b9b99d200ff1c1e164
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:ccb5a5887293e1b198c8f97fa3c34548b69ee9f7c1c2d81e7f1acae74b5b2436
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:de1542ee072e160dbeb698ee55c9981253efa4d01e09d603247aa09cf84f7c0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:70fd1007b702cca0bb409e183a31891112b0b42612b67bbe4c9ed9b104b024d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:6a259998cc4c23a149e80828013e2c87ed225b9c72ab085897a1aa43780a3de0