dhi.io/distribution-registry
3-debian-dev, 3-debian13-dev, 3-dev, 3.1-debian-dev, 3.1-debian13-dev, 3.1-dev, 3.1.2-debian-dev, 3.1.2-debian13-dev, 3.1.2-dev
sha256:5435e38fbf63d7fbc79465a7c931d1032d955a6c18f0a93a3b13c0c4d7e8901c
Manifest digest:sha256:19e84312183dee101a8e6310868ec30dcb12fee5e14eea126105315fb4e0cdb5
Size
50.52 MB
Last pushed
7 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/distribution-registry:3-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/distribution-registry:3-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/distribution-registry@sha256:9cd4b6b905f38d2b9cf548ae816230a28d37f5bab8dfef9e4104b2b3cd63c0e8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/distribution-registry@sha256:6193399032fe5640f2d0d8b7d6f4c83198682c90a031308c126069683e52eecf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/distribution-registry@sha256:25baa1ce7abb78fd6a68397dd53dbb0ec221a983bbf5a7e743fc8d1971e68154 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/distribution-registry@sha256:1a19894f95f0b248410580b6e9c1f69282b5ffae69d7758f5052879b6386faaa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/distribution-registry@sha256:173cdeb7d1f1c2f23f0bd6f96fed859c0ba211eb0710db0826e5d4bd852c8c7e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/distribution-registry@sha256:2d0a22ab1dbc71883e4e4ad9614a0515cef35bbe60cd5a38c9cb477944a0fc26 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/distribution-registry@sha256:e9643a2a5b87a8f988a64aa9418d18cc58748776d1a89c52c3b2342416bdba4a |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/distribution-registry@sha256:a85f77bacb59aba833fc7b53a426ddd1b7336c6a04d877cd4ef8ab51c5563978 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/distribution-registry@sha256:3bb2819d050e406f3dcafb09eca7055855d84cc860ff6d0875727f1b09bdf05c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/distribution-registry@sha256:683c0bcee6c232980777d157bd3baacce536f215f119c0acb6c3e7ca8bb1465f |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/distribution-registry@sha256:00047b44ae1f090fb8be7137c038cf794c4039cbd088b94b280eef6fd34a58a9 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/distribution-registry@sha256:e415370c75f2d1911e900e497a68eca5e4c2bb6f13963caeafe108227e72e8f9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/distribution-registry@sha256:923eef9a638864a6ab8a7356e74f557b4827d6f7a966e99386332b239ab274e0 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/distribution-registry@sha256:5b5ba6694c53a1efbc9ab1bdad0955a287674317cf750a1307e887c868f026a4 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/distribution-registry@sha256:740556f6e40be2d1da19eae88e5636d69454520e5bef4ccd469c4516f22902c7 |