Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:b3156a0f08f2b89729e20ddfe7a03a7f337ed28efe557830d98a772525c449bd

Manifest digest:

sha256:2a7f1a7231c347baa305071057009680cee243ff54c24f8838193991dbe7e423

Size

24.34 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:fb2093318d138e425c5c3bfd1516f064816989bf18a36ba93165de4feb782d7c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:376f11a7b0427905ed3db2fc9e25c69709688869d486aa1f5be66d59480f5fe7
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:bf6e8cfabdb43c2a2dbab6d640fb3e9dbcd89bd58a25541c805ad843b344b682
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:34111b105a1c12c189cc4ea2d29aba714dd983b79188da3fdff3a7377675d10e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:58f61d6a6034998204482adb85b7ae82188bb54f9b91bd4cbe25baf2ee269ed6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:8e6b19863a9b87ae5ea105e082aa04b8d326deea957d15fee785c2b6a7671672
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:342f81065174f9a8efc402a7a775783e6a31b173d9a4719c763a02bd609d9ba1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:bede0a45c725f9d7c898d11be12a890f12c20274ad1e7e3287b93c9b67ca9762
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:12fd5635b2691e3c4b73686f4ff23cfc8d9ac70ab1414ccb17c81ab08536230d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:c031789b02a78740a40249112ce06db9739aaf7e1a20004851fc276ce480d928
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:879bc46e264c5e9fe52d5d3e2d689b7ff4eaecc854bb629d9015e7e0ecc68834
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:f923da458405e14bc54d19ad13b981471b303b865464ac64d2306b098d12b4d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:5c49dbd049eeba7eeff12acda03f2ce476066ca344dc08a6f836d590276a48d5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:97a5ba68883fc9466ba5d1e244651b9a43aa6bc8b3994dbf5deee7b7f17e0516
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:e3775731e176d5abdeb846e1e0490bb0da404972f0bcac6c00dc2595c9471427
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:25867a5ac37bebec5110a01548f5b0444dd28ce54582daf5857c81c39ee7aa40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:e0417b566b35968557348092d1a153bb903c744fc13375b2e74fe893d9491a37