dhi.io/polaris
10-debian-fips, 10-debian13-fips, 10-fips, 10.1-debian-fips, 10.1-debian13-fips, 10.1-fips, 10.1.8-debian-fips, 10.1.8-debian13-fips, 10.1.8-fips
sha256:e1012c65bdfabbf92c91a8d4e79492f889681ad3f006a963a2285567c031590c
Manifest digest:sha256:2885a6c2b4ae21cf716ad8b6a42789e3f9c254001bc39ef41323918a23dbf59e
Size
20.94 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/polaris:10-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/polaris:10-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/polaris@sha256:9b5b52997d0b64d19b88a35c0ec37eeb21ff4ea2b8d5ea04285c2fff0128eff2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/polaris@sha256:9be4f7921589fb16aa6855d829a1daa7502145b6827e9fdc4098d85da7ee11b1 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/polaris@sha256:ad9edc011323a2730d2bd9c14ba0ec931407bed3bef97039289954323277fdaf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/polaris@sha256:c2aa315340ea2290dcef8472c49e2f186c4a673648aa1ebd68c27414b3ca6fe4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/polaris@sha256:a9f21a3545b969dd9fe349b88ae22477ba815bdb020fdbfd5a78563805b40988 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/polaris@sha256:2d9394021b7f04691aef7a467e2bc971953e426018ecc94379430ce55afe1bff |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/polaris@sha256:af3fff9561d6c5f2c87af29be836e81374cade6a4541ca2bf96b85808b863706 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/polaris@sha256:ed878a5da01be453fe079e6cd80802707708b6d37db4d416b68a44276c77a036 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/polaris@sha256:4e05b2e69093b0071f3ac6e2ae21fff580f00c0e08a31819869f0757b2d2eca1 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/polaris@sha256:154fcfcba8e74b274288a297274ad046063e31143c656e05167af3c5334d4f29 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/polaris@sha256:b4b87cf2b00817f2bd4d42fad9abc133cdd0130fb27ece405d5979354abafc2b |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/polaris@sha256:15e51cd388f685d40e8b17828f1cad96698270b77e11cbd10fa94d2a2b4d2019 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/polaris@sha256:882956f2c631d60e6792cb831b573b7250ec5991fa8986558acf803ecd1a3fa4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/polaris@sha256:a2019901c7de4c35482705f025fb52d60a6b58baceb0f330d5f58c7418295a51 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/polaris@sha256:e1dcfdefff9258887626668382b42ba39ff0e54f447301e19b96a4e6ddd6bce1 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/polaris@sha256:9c2ef25c6cf74696c55aba23af1c86461538fdcf2d3a8f4bb66dd7548d284a11 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/polaris@sha256:15444a8454cff340bd2a8819bcaff93988526f34ab60710e2bbfc635421b5134 |