Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (compat)

CIS
linux/amd64
debian 13
Tags:

10-compat, 10-debian-compat, 10-debian13-compat, 10.1-compat, 10.1-debian-compat, 10.1-debian13-compat, 10.1.8-compat, 10.1.8-debian-compat, 10.1.8-debian13-compat

Index digest:

sha256:09f2c59a2231051797af4b130032a8b83c3f620b5e376a4f3b986771b1962999

Manifest digest:

sha256:58dba6cf75d30bcb41b2d8ddd0ea6e8329d98dcf65acec1d3b9f8f91c55fdb3b

Size

24.87 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-compat

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-compat --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:6d7bc7a5594f2457b3ca1f2ed85191f2a3cd14fc167657e8384705a14045c778
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:a5a69ce74a0c0fc4f63a618dc45527a05e0490716ba82927d46ed35066928b49
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:863d38a8a7f56b3316edd57e29ddfa645a63bd30dd398363ef504cf22efb95fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:51e7ac99c27862b460638a3c635f9ec334c176ff7c0a60ebd53cebdc71bc68fb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:c1acf52be1047a32513ddf9ba3f5601ecfd387b4b2f0900f75aa3ab6e07947c8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:1705556f1b672fdffbae1ec43b35a423cddf5062fed16164736173b0fa6a7969
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:db3bf370277975aac565c310cb779ec53f840e4fe5385b6cdfe72fcceae5165f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:d039e255a89e226c02063e1fea405f0cc7e14320e3070e3445c8bee4b4e387e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:abd7e67766d92230a8d1669acbf6c4d06e158cb94c8fb0527a41fb72601924dd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:81fe9741c45193850de90ec8e1b98a0cff63ab414d94da239eef1d31f8f4f940
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:c04231c86545c50a5871bbe33b56d55e678b49c8f649c60bab45dd6293c950b5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:67edb690113203329c927a5e2849abf7c1f127145418ed15c02ddb2655c9f48d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:8abae56b6a90f6e4ae43fd0c249d075ba6a6403411eac0a5854dc515bd1db81a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:da1846ba1607e3f615fcd5bb150493221da9321d14f9ba2d848112500bf9cf2c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:ea5c7d8caf0f3d3a962b6a1a4d4fde6d5d681425cd14d1e3d44e64d846994b12