Sign inSign up
Homepage

dhi.io/homepage

Homepage 2.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.4-debian-fips-dev, 2.4-debian13-fips-dev, 2.4-fips-dev, 2.4.0-debian-fips-dev, 2.4.0-debian13-fips-dev, 2.4.0-fips-dev

Index digest:

sha256:dea68e17cb0492ff6bb549655203f8c11a6ba03a2a871eb8ecc52776eec5506f

Manifest digest:

sha256:3d27563b92417f04cb6ff46ea87cd9c252df50a68e45913a0affc0a3343f0cc1

Size

71.94 MB

Last pushed

15 hours ago

Vulnerabilities

1
8
14
6
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/homepage:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/homepage:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/homepage@sha256:cd389f8ec8771af018a6758f0bca8c1d70cc560f957ee7bc39b1898c91fc763e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/homepage@sha256:025732b2da0e59e6ac7cd2ab967880e90e43c6a51b9517892156d28b89ae22b1
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/homepage@sha256:843c370fca29231748b0f2913a979288e46bc988e61e2589d204ac80eb2a9a08
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/homepage@sha256:b66f766c9b8c5434a05bf8929c8ff0900d5974d448f0b5f1663d444b05c5a78e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/homepage@sha256:9e226ea2b9ceffcd5931f2c36abb535324c112c2fa71e3d3926fd695624d6a44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/homepage@sha256:14c1512e83367e07dec4ca2671a3d0e4e238e83867c3120c94aea62bc93a6098
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/homepage@sha256:f76949d3d2e472eddfc525844485608922672f04fd00c6f1057beeedb4a797d7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/homepage@sha256:2936ec2d5fa45368ceed9d426d58eb27f016933446be16485780004b3e2450dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/homepage@sha256:bccb866be88e7d967c16eef420cfb5e379e78bb7ea2793bd9ab20afedb64f87f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/homepage@sha256:ced157916ac1f70de3398160c45d1b1db1a137d121360cf17aedf60e1ee87e25
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/homepage@sha256:1816e6327b118a6c46d30139ddd33f057f3b77adf2acc293115360ac1c25f419
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/homepage@sha256:1cc76341241ed5bda1b28048ed95d8578cb1414952e9456423f1e7157cb35eb5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/homepage@sha256:f2bd2a95558568c6b60ce493c6f8ca4beefef0323ddf3659e916faa322a63afc
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/homepage@sha256:6e3c33abb9a89b59917ac540cf72b42c299a906e95b48fc64af96a20ab408be1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/homepage@sha256:c65c14d8d9d7fb11545817d7389369efa2d6fef897f92f9083d86359872abf98
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/homepage@sha256:2f554d9a71f1c9921b092276e4be139dcb635c9f6e451d91052a52a0b52a883e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/homepage@sha256:90274ea1cb80bda365ccebf0b0134ac87ffd0e7d56e0df2ae8d0684066d19b2f