Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.1-debian-fips-dev, 10.1-debian13-fips-dev, 10.1-fips-dev, 10.1.8-debian-fips-dev, 10.1.8-debian13-fips-dev, 10.1.8-fips-dev

Index digest:

sha256:cb2fbad479851c7b87175d2ffc0f725f26f8f19eb6eea4736f322caa0385f379

Manifest digest:

sha256:beefa7977ff9f0334cd4a88a0f300c2206a5890dcff8a403dc960ffc3d36f41c

Size

36.09 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:1bc47c669d600d4b92380bc4d1761772f49ecd292df62d6ce8b45ecda8ae4b44
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:875d08579a04d145344f28de4b25f77a2004a11a7616ba4f060444f206e925f3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/polaris@sha256:b3eebc5df6684e34ae74bf69e8854705b476535bf88bf3fa46bb46e1a4466695
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:a95a18f666d4de8c93c64431f7df59be2030272c35ec057d9c8c04c624e097ed
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/polaris@sha256:c8fb55f80e609a424ffea8ab8c6c673549c566d7f04007f6e4b31dbf4bfbb57a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:51a3ba38d2a71910538e50609b8b5e29eb4c2c4c4828659dc7331da56867dd0c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:b4363443d7564c5c901573f2aa6c00c4964f65a66824b5a04c933f7cef7730de
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:fb3edbec2bb9259aaf06205ce0a6f8934ab9638bfe2e38772b022be0aaaafee3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:a2b45cac00b819ff4e669c959bd3c6f7a783dffe4cbb49538d555827dcee5b13
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:5fda18f4e951816c2edca4520b1c86d533f12d1fdc447032a8999eb68eef346d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:45ac7f917488289cb280e2d2bacc0acab0501560ebdbc244388bd3afc130aa87
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:6607785c9d125774a91c23b6c8ca83f316dd1478341a9a0047eb0c8e2bba95b6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:3abd552ab523a288b9c48a75769e94cfac1a5f06f33c49f3e8abcee73722dd05
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:87353015c9d6f1d39338dfc28a3c9d39f7a69d397826f4a6d477fb43e8648668
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:5e227ae607468fbf6e36b38bb151fb642fc8add4843674d78c5f0d40a47a7f93
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:77363ce3879aaac807a9c753d3dd0f5b1facd344900423f75553d5f67f29367b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:5f5a340ec00540bf2df06ef4503e0c59cdc4fc15213c4b44b2b91ceccbf94f1c