Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:e73b76f7b1b5741c7862e273755a88498b9947a536e28534e75e076c00ae7638

Manifest digest:

sha256:2abffd216ee210fa239b1cf7b85b0e15c37c1acd2e0e5a52705b6758a9a4f514

Size

24.34 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:9ca15511b944d49498ca21072ce8b5b7d0a87d41eff4f6777318a9d4ff33be37
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:c480c9e38498d0f9a64a310d76250f42a472b3a320b056ca3f7d622320dbc7b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:e06b490688c6e552e217cf63f62089a435e505273706e4c696da5f7a03e788ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:f063c03add8da7599500823e9d4a90e0bff663615033cd5becb974f1f1ce8e15
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:64fe3b14e09346251fb194e2e1fd670797f5d78a8d4366202606f014521d1ce4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:b8e84721116c054e8943ae8dc9850e5ef91de7074bc542f7a68e1f9debf4e183
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:189ab603853dc6152258b52d29eed7643e8d392a1c5cd07659d2e2a85a5feb82
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:f1371f3af154137d88582cbf128a9391660d13c9903c799f72f36afe17bfc6c0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:fc3a2539ab6effa2eb9998193d6891595b35269bd1cc25070078484741bf66af
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:6aaa7a2797ac87bd00a604bdad863fd7a289fba8804200729823c0c28c107a91
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:1b0796c8fa53cffe1e11845d3a16556af16718e5f93b4610a8f257f94823c3e0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:11b429cf7d09317c2d92b8395b83f370d0bc770472ee74db1e7d016512543bb1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:335c464858a475292a967928c9fa926f5e58918bb54a2c181a6904f2beee7069
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:163629a192e72d899e854cdd0238f38831d0d4178aa3fc9ca24497b0667dd121
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:f0ef529b32b92b325c78c83bec2027c19d101974fd88e3fbdf056dd34851918f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:20bb8d8bb375a06c6bfa800ba10fec6880f21f09e8cf982250c9f37989ca90b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:4b188cfdc6fc2478d4618cc17eb0f2538156f0b93409333af59f7568df019dcf