Sign inSign up
Nessie

dhi.io/nessie

Nessie 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.108-debian-dev, 0.108-debian13-dev, 0.108-dev, 0.108.8-debian-dev, 0.108.8-debian13-dev, 0.108.8-dev

Index digest:

sha256:c70f56088b4e502813867dd1212ee0f2b8c5493e8e0e5bfe0ca30efb1a56a088

Manifest digest:

sha256:d1b9ee937a0bb4b2433e45536f15a5a3fa40d409ce268c0ccb68492351151543

Size

295.15 MB

Last pushed

8 hours ago

Vulnerabilities

0
4
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nessie:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nessie:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nessie@sha256:9f727d173bdc50eff412ef457dadee7e210b98959a2f8842f1841f7e40be8bcd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nessie@sha256:4a13a9cc132f16233ef0edd62c7b76d675abac3ce286ebdd04ca7230f73b0742
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nessie@sha256:e4f2c91cbdfe158acb93e948b208665e4a24402edb420308d062eb80adbaec6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nessie@sha256:ccfd9756d9c5f619876631357c48055e97e0a15987ec8170d5d603c3d9f32344
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nessie@sha256:7ff9043ec31ac218801864cef871fcc2055961b8a32c0e5fd346be7ab977a56a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nessie@sha256:fc7dea3f0cc272c2d6c8cfcb78ad864092dd21b95909ce13bcb8455174b246d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nessie@sha256:a193bfb30af399f09e9d13cb19832f58dd2136584d64586ee2feefcafb44f9ea
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nessie@sha256:00c72dcf37bdfe6495977876432966ada5aa468c25b030f89c77de1b33254b8d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nessie@sha256:d572bc9c4b55a184c578f3795562d7bd732294ffabc434b05fe52959111b0e14
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nessie@sha256:478551e8ec49dc50c624ea773f30325338a27c83d2ccf9d4a4290372a33cc21b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nessie@sha256:39c8ba9f7ee554bb81da5dfab95ecfcec0a8f72cc876e724925edd00eabc3924
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nessie@sha256:3ae2bac7ee449de3a6c97bf3d40a8968eb94348a444a55d510c2b98d0b589641
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nessie@sha256:f96943adad44373338e11b8cd3ba01f9a382d68b8abb2a1a54f1823343be8f41
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nessie@sha256:c7b99980172df8448bf8fcc8366528816a9ac164241a56e625ea1d2a920619f6
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nessie@sha256:604f073447120c1c346b62a64c92fbf6fd230d4eaa59b5fe4adb55066a00bc38