Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

trixie-debian13-fips, trixie-fips

Index digest:

sha256:5aded52b05a424b39155709093244439df87e3ee01243cf97dfca8f02d78a410

Manifest digest:

sha256:70bb221b9c2a6297ece923a200ec8b926e3f4fcced0ef8ee4c107e1cf2d8f134

Size

13.37 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:200140258f97b464cf2adda58a9884db55aaca911b87e5bb4226a80111cd0d1c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:044f878f60579d8f551e20a662f3c4f381a22ea6cb4221f34f03f18888d04252
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/debian-base@sha256:4ef95a78f6e607ee49403e9230e4bdb947261ebef01d6250624438455409cc77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:d4080ee06c5f46374832448fd48d40cb2ad221e84fa161205b4ccebc5e51bc2d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/debian-base@sha256:616d43b36202b3b56f68bed67635b7b1286200f4dad5504999d528db82525365
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:6367ecc0e5fa487c18e4520a63e1c7c39d1209f6354ab984b25c43905f2ba870
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:7439d1e9e0dd88db4d99b23c91597fd70f4363c22527456daab38c742962a9b7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:df55b8f823d6200838e62a55f1dc17f608d50c808d77b1d53a492880e7d0e34b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:18c9e4f39ed4e15253c9a528485add274609eb4356b46ff48106a00d15704e77
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:cbba674e9737a63082f33fc4d2c006bf92fbb98f5f82e4f1445ce4f3a66c690e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:65fa31cdba103fc987e7db6e764e08f3ffb215aec1b6c3030f823a5507e6f997
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:5629deaf9c3c1d9acbf14bbdf21751b8101d8b9c26e7d6076a39239312818bf2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:35290fd554e7133b1793d032d747173b514ccdbc22bbbca234e9f6596b3951fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:91d85f5522b61ddba3e9f6cdc9ba7bc06cf5af162543846dcb99e8d3cd54fd82
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:43f72c045ca8f2fccee6ba7f7fa940ebf180ee47b6154855ad9e0508c2b84953
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:29db24a71ae16696398c4719ddd3958622bf601268703cee144dfb5ecf57ad80
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:78fba95f0ca1dfe9ad246fa9d6e9b9e6f6dfc9703af47684e8b4f31c678b1454