Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips-dev, trixie-fips-dev

Index digest:

sha256:c6415b0b7a6c51a888042e0f30797505ac7a684452358edf15b138baa897fd72

Manifest digest:

sha256:a101b20e5cf93ea8736656ed08cb3ff2864498b1cb8b76ae93383ed4e9c618d1

Size

24.34 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:fb7e1ed1de887040f9bb62d5141f3e90f625304f4616d2a5a67e496d95a7bea9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:9778efcfe71fba58e03c5163e3063bf8c77d0ebdec23921a0e79af71c28d6117
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:b5e52cacf558d8cd1673d175b13ba24e94d7491e754803066c1d3e8ad15c201b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:2c56c1afdaa4c84162f229d3be7bff7920973fde2fac915bb673d16e2cf1efc9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:7bc1ecb0656c3f6efb11ca83f010bf2ca0b9670af0da204efffa86bcbe82eb2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:70a0928284b2b6d13a1fc659ddfa654e4a93b7142de0f9621785ff052dd8e662
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:43ec1fc45f76028dde06841fa44450559c882fec0f49b28010c0904b7e333fa8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:23a9acb6b7244ca2735daf5e58b759b03708f5d90d099f5b9fc23b2c576ca359
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:a7d13ac0c648be3e88658d9243fb5f345b09beae30e8ae3795e3b14e0fe619c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:f3775855fa4a0e3eec39b182bfc390b3b3bb54d157614d59c6201fd43e052044
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:6c7719ca3109619994db238906e4ec032c7a2856b701887aa0f58fcffe3b02c0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:bb945542834a28c17228c2f1e459353030a24963b0517e64c55fb9d7840a4a01
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:6bbe338648df56a62d36d83c058babf0da7406fc3e8b91bd735411edf174c107
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:294a1ff21b7e0ba9c3b0f92544a4726a24b9de167bb3bc3e8157a352b5ff30b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:ce0cf47261b59265297e10b855b8f0c30eb07b9ec7909ff6cdd64f15b43efb0c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:ea4eda03a73eddcd3a9e8f475bc9ff6feeaeb11527aa2b9ef3d67c9c4e9f38d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:aed5d77b5bf73e750c6a4dc354bc0c0f664cea97480434ed0ccd11eb9a7d84c8