dhi.io/notation
1-debian-fips, 1-debian13-fips, 1-fips, 1.3-debian-fips, 1.3-debian13-fips, 1.3-fips, 1.3.2-debian-fips, 1.3.2-debian13-fips, 1.3.2-fips
sha256:7c727e5006e279dcc42fd21ce8b592f11727758c68331f2c4685bc174e248555
Manifest digest:sha256:d3699bd3a42ceb0930eb628a1fc734f50a40459c3f30621909e3420b0962ee05
Size
12.23 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/notation:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/notation:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/notation@sha256:b6378c746f9878dd202864d39eca9be9a8ce8f1c5cdf15796ea85dab794954e2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/notation@sha256:9a42685f0a71d9dad3044e50adcd93da653e58ad6c1d5823c7cf16237380250a |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/notation@sha256:19a890e96a99d70c6406dd04f31ef3c9c3ea442b5005a7888c24587192c23e01 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/notation@sha256:6b2442af857e9d8bbd0c42ee8e3db0da01693251acabf0be980cbc3653e91856 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/notation@sha256:363c3a8e5c87e60d934931fa64ad388c1e652a183c5bdea024f5803a2655beac |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/notation@sha256:78790de062efada139d8aa0c950e3372f1f72b4af30231ddef0e0b6693e65c7d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/notation@sha256:8fb48be5e6c9ad214a60ebe9f61f8ca8a1fe106fde6582af7bf4f6e079d8fb5f |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/notation@sha256:4ad7031a1883934ee5c84f61078a887ba63d19d76c7d1340fbc2b2a68aaadb19 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/notation@sha256:057bd9aaec659aa9f528f0a708889c1895d098402eaefff00ec26b1c119d64eb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/notation@sha256:bebcf2566c69227c0b2f550eb06348a379b45de9684868120c762d4c6aabcc08 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/notation@sha256:2a675956ecce87e6c1ff7606d1451d424ecc58657d94e8aaa03a10dc4f23e0a8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/notation@sha256:566abf2f166f039ca14c27ef70be24c3e2ab2791209cb6eb0558176a6ca7ceec |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/notation@sha256:7f598b958c2e1d5b2b48a260dc4301fe4a6e8f16d56a25119ba70857d19e5dde |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/notation@sha256:8264fe6c02ff3fa77940080563974442ba981dc064454d38450af38fce3bd1da |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/notation@sha256:346c6dde42f53498f6656d72bc14a0f9b6053b8ea40fe424f85c834cc5a19402 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/notation@sha256:e746306dfb8a403f6c98ff2d732e282b91e3765b21fdea8c9c62e17818dfb9ce |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/notation@sha256:1bbea2e837fc4c735ad6c0d3f13d80d40bf19f9e9e11938c24ea7526c39098a5 |