Sign inSign up
Polaris

dhi.io/polaris

Polaris 10.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

10-debian-fips-dev, 10-debian13-fips-dev, 10-fips-dev, 10.1-debian-fips-dev, 10.1-debian13-fips-dev, 10.1-fips-dev, 10.1.8-debian-fips-dev, 10.1.8-debian13-fips-dev, 10.1.8-fips-dev

Index digest:

sha256:5a3ff3a42b44a40289719068870c9d3cbfae7e4e006f228c12a3858304a9db55

Manifest digest:

sha256:ed469e502f39e40bfc2663db499e2bfef526d289293aa4a641722b779fada557

Size

36.09 MB

Last pushed

12 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/polaris:10-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/polaris:10-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/polaris@sha256:b874e7c6627800eab2ef33f47a3fd79c403d26d985231cd9e4153f5ca0fb007c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/polaris@sha256:87f0380c50fec6f98baad884b5b9d858360ee71a7f8beb76a40967ca01f0f705
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/polaris@sha256:071aad97d55200649980936e758434926f44ec4852ef0e887e0c989750513bf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/polaris@sha256:5a700b074ebf5bff08b882be53ae1496b7c78c3036bb5dce6a64fdd9b6a701f3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/polaris@sha256:92f864c2c99241069768e5f1acba6df4f12894bc31bb13febe5620173c26ea93
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/polaris@sha256:c22be70591bf0ee23f6a98abff07741bcfb5d9c42ec70b879538d6808c74ee72
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/polaris@sha256:6a0941a8eab327f21a26686accddf47911a7e83f26c042d9d857fbb79659bbc8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/polaris@sha256:2ddd7fa1afa81967586e60aa55ef9dafb90340e48232d22e64d050dd8569b671
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/polaris@sha256:3d79c660d0453cdc18bf4aa6c1f7924b62c7cd240468b99e8506c67900b8399d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/polaris@sha256:1f62eb4037e5c7b36f01549f4e8dea837c7d55947ffe205887c0b8b1589a5d27
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/polaris@sha256:27ca001d0604edcf13892d36cc0d6e144e2746c371d1996c29b4c85a808f06b5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/polaris@sha256:e3f76b85613e9eb41762c47205d56067da383baee3e6ca522c460a418661860b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/polaris@sha256:5fde5b75c2fe8894ae45ddcf138aa0124a3a997ecc7b1f24db3cf3d5cec04234
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/polaris@sha256:bf43307ebab1dc019bbbec5ab7ca01bd391902adaf131e787c5ef379e19210f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/polaris@sha256:b7078689db19299468ac0b916b2b646501f6677b61bf73974dfa51f1fae61fb3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/polaris@sha256:6df14e9b302cd5ee79525d60de1ad3bdd82e71739d314793912990d8f36c34b1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/polaris@sha256:b692cf1f55b9a11c06da748b23b43f575d9c42e95bfc276a94de50538302dea4