dhi.io/polaris
10-debian-dev, 10-debian13-dev, 10-dev, 10.1-debian-dev, 10.1-debian13-dev, 10.1-dev, 10.1.8-debian-dev, 10.1.8-debian13-dev, 10.1.8-dev
sha256:6159e363ea8899fe1cee150ee400df11dd3160dd86a291fa61b98f72c40a2ad3
Manifest digest:sha256:eb39cbad1c1f87ffb8406e4752b4de15127cc502a1bcca9dcf0c7b502f2bfb1b
Size
35.34 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/polaris:10-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/polaris:10-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/polaris@sha256:a60c4894b0d08a7549197b243f09897c79597d17a829889f0b17ae56d9d6ae17 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/polaris@sha256:d35c6748becf9e813157903994edd8b6329920262a2f58370f7f607226b221c7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/polaris@sha256:88c01e856a5c31934f936ebeb5b5ff380346ba9e48482c8cafb3de72493479ee |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/polaris@sha256:392a61045e04913046dcd7cca73d46400c8dbb2355f80c4ea079c00881a34a2f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/polaris@sha256:2e737cdf9bddc4d800ea0fcf4a98444f956186220d2e0365ac1444c0b39ed146 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/polaris@sha256:dd70dd7b3dcc894a81542592d8b57725ddaea06d41bf58fe0fede9ce5bdf784c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/polaris@sha256:3c04af18924235006c755427f42e08bc1379f812d33b1c7eef407e89009bd3e5 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/polaris@sha256:7ebe33c33730ef3c38cc64d8940ada7f75c47286fba0bac4d79596e5b7e280ca |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/polaris@sha256:8ee8a398fb529e734c497b428106c8e97544430a5ea6731e85a17400db5ab052 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/polaris@sha256:3b43903a1bf01d697ec9c895d63b7830b1a31a2b03150bbe0ba1dfe5900265b8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/polaris@sha256:5ccd50a31e31f21404b5088fde26dbc68e1fada16316614d9c3655b80baa4769 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/polaris@sha256:8786fa6b3543a4e4f70a2b97f5601c48f2e25edd4cc5c879e4305e422079a13f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/polaris@sha256:6f4e014cc481ff92bf0babbc12b94245430140983a08ae8f4f4cee8ec3dd9c33 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/polaris@sha256:6aa225f897682b22afa2232ede34e891f0e74bcc82618b1a7bbf308f80cd1eae |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/polaris@sha256:be0d23ba5419b112fdbfe52863d70dd9fa455b7d2e36c49428ada69c3edb3b7c |