Sign inSign up
notation

dhi.io/notation

Notation 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.2-debian-fips, 1.3.2-debian13-fips, 1.3.2-fips

Index digest:

sha256:7c727e5006e279dcc42fd21ce8b592f11727758c68331f2c4685bc174e248555

Manifest digest:

sha256:d3699bd3a42ceb0930eb628a1fc734f50a40459c3f30621909e3420b0962ee05

Size

12.23 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/notation:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/notation:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/notation@sha256:b6378c746f9878dd202864d39eca9be9a8ce8f1c5cdf15796ea85dab794954e2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/notation@sha256:9a42685f0a71d9dad3044e50adcd93da653e58ad6c1d5823c7cf16237380250a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/notation@sha256:19a890e96a99d70c6406dd04f31ef3c9c3ea442b5005a7888c24587192c23e01
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/notation@sha256:6b2442af857e9d8bbd0c42ee8e3db0da01693251acabf0be980cbc3653e91856
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/notation@sha256:363c3a8e5c87e60d934931fa64ad388c1e652a183c5bdea024f5803a2655beac
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/notation@sha256:78790de062efada139d8aa0c950e3372f1f72b4af30231ddef0e0b6693e65c7d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/notation@sha256:8fb48be5e6c9ad214a60ebe9f61f8ca8a1fe106fde6582af7bf4f6e079d8fb5f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/notation@sha256:4ad7031a1883934ee5c84f61078a887ba63d19d76c7d1340fbc2b2a68aaadb19
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/notation@sha256:057bd9aaec659aa9f528f0a708889c1895d098402eaefff00ec26b1c119d64eb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/notation@sha256:bebcf2566c69227c0b2f550eb06348a379b45de9684868120c762d4c6aabcc08
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/notation@sha256:2a675956ecce87e6c1ff7606d1451d424ecc58657d94e8aaa03a10dc4f23e0a8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/notation@sha256:566abf2f166f039ca14c27ef70be24c3e2ab2791209cb6eb0558176a6ca7ceec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/notation@sha256:7f598b958c2e1d5b2b48a260dc4301fe4a6e8f16d56a25119ba70857d19e5dde
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/notation@sha256:8264fe6c02ff3fa77940080563974442ba981dc064454d38450af38fce3bd1da
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/notation@sha256:346c6dde42f53498f6656d72bc14a0f9b6053b8ea40fe424f85c834cc5a19402
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/notation@sha256:e746306dfb8a403f6c98ff2d732e282b91e3765b21fdea8c9c62e17818dfb9ce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/notation@sha256:1bbea2e837fc4c735ad6c0d3f13d80d40bf19f9e9e11938c24ea7526c39098a5