Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base

CIS
linux/amd64
debian 13
Tags:

trixie, trixie-debian13

Index digest:

sha256:20079b51710f0397da5e056bfc7156b6aafc7ff3aa4ef4cbcb0b0f1df99cd8c4

Manifest digest:

sha256:72e7c81ed3db6ffdd78d5d566aabc7b2cd27eff24927fdd348ff7f5835385ea6

Size

12.61 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:c54afa51ecf18b1bd6e14bbb22a1f1bb55ea2d95b6d009b356bee4d108aecdda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:846d0ed21a4a1c64984668d22fbd2ee236c165a19699fcdbdcba3f620e45653b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:be8f851a65bb4d97705b157ebb2f8ce34ac0ac46cf13c24eb191ae5293d0b372
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:f2ff7b4ec332dfd563382ec1da543ed2aae56f30042f437f5b33320c0e166315
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:262d6afe23edc87f9d34375ed8b7ad876f2ab1784b66c6985a137d65ddc7ef9e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:c47a6c8db6874348edf5beeaef5916195d9c9e4a93e39ccf255d446bb182bf03
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:a8773ad6cf4165d1a74df876cbe275efc2c0e0a7ad5c3047c8f689bfdb6066bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:f1534eb57f1d11637ca7f6e186ae95b56ac3a92292e4b5b9d86a4f74905720bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:070236169f3e0299af2fb0696736bbb1c1c42b152775a8b570d3693712a4cd1b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:93fdd9cb973662e9cf469824883b378f4f64a3a780f06daa8f9c8a1208d10548
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:2757999c6f005d204cb2034c939d5ce9c714dfa950749dd05252c7d61bafccd1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:c32f03b43435836340d0b8f1271aa8cdf138448d876ae2901ceb4c6ae86d26e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:84302df6fdaea57792ef32a9f661d03e8604c2067dccbb568eacc919a0dece02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:dec58b54668c5aeddcea1e7270dc0602375d69e72d188a76db30f1c70f4cd0a4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:2ab25d104fb609a0d18af241b3170319ad423b5be0d455a2549ea6a77123be39