Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base

CIS
linux/amd64
debian 13
Tags:

trixie, trixie-debian13

Index digest:

sha256:8de63b28f8dfe1bd5f1ec8597fa241198b7f9bbe0597316d351f67195cb5983c

Manifest digest:

sha256:bb14ed60c885fce1731aa34c0bff91d5728a2d904ae943509a0333e6a34f2731

Size

12.61 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:5d32cd03e6c6f48a7407be0237d03ad5a880ab5c1795d59c770c6fc82ff69f9a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:53e1458397ae2af23b77d2dc29d566ef42abcd47c5551886f003111116f548f5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:8c2ff4068e9420ba712c2d02b999a00104dca796044e79a627665a195d367255
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:d8eecd294196332f48853ef01a3d38cf2224bba657b1098727d30e6747ac4630
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:78c203282a438dff3e5303c210f6fe5041c311875bfaf222af82c9e49c073e0a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:f79b23384fcd3dbcdce8bc376dec23fa0b056c131f48cc2e1a16f19eb7a19ca1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:98b29e4255ea668c14b86feae7a9e72f5d17be8864a1fec9fb2d4ebbde7c3f29
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:834f11f7e5d05e2667f850bb769c1c938e3278f5e346b5cf453438f386f0f250
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:0c3d71b43d84ab30241cff9c6a62ae92f3e4890e5734ff735297e29ecd0e99a9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:80b0633b398632bc10fee1946bf551ed2efcfa9d90da08a3b8e22fc224173ed4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:2f1e70610528154b3af23192c32f7efcfb19dd66046ee4f1f003a62e7851cfe6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:7f9aac2bda17afe8276e129b3f8323423643e66d72e549020d0012d087de3c65
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:47f95771cd50e39afbdfc638e0bcc94c1e7cb23ff553ca4b5ec23ced96f7dc13
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:c8492e472e61a1939d1f41cc2c4d49227430a880a98589e236d08097a672bd24
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:025a5e63376ec6a31a4f61bf828fc55a43b19d7afd6259ca5274412a31e1091c