Sign inSign up
Static

dhi.io/static

Static (Debian, with glibc)

CIS
linux/amd64
debian 13
Tags:

20250419-glibc, 20250419-glibc-debian, 20250419-glibc-debian13

Index digest:

sha256:36e47944803c2b1cc636b9553ede0fba7197d7a5348d516669677d4c20e06f90

Manifest digest:

sha256:17bdc56e96c39883e6befdc6388d80301e417577940f7f6000abbff7496cf1b4

Size

3.92 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/static:20250419-glibc

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/static:20250419-glibc --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/static@sha256:0c3d5365c763ea3882050ee7f8c58a74a592db954093470b00bdae0f9cfac668
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/static@sha256:b41238fb552e2a68e3751551a75f32d8a5f2c8bc7bb79868c27fc37bfe142329
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/static@sha256:2a79fa091bbdbe799c3cf55f7075ee41d194b8cac03c069df7b7a0733b8de5cd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/static@sha256:6d38cdef8f94b3e78dd0f397427f72777f85dd48718ef10a01bb1ee9c7fc6a76
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/static@sha256:d05bf84414375a9ee72c78e94b83ee06bf9e00b5161aeefed2084d28ece7edba
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/static@sha256:b94d63897f957380a4b33289381fce2664e8df5f2a4efd02650f185d6a74cb5c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/static@sha256:4c4512767a9fb8f3b7878975a3c78f446f189221aadf4c4e86b9ca4fecceb272
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/static@sha256:496a42b5cdfeaf6ec4349402049645ce79a7f5f2b5e01299fdaa0f2d1efc51eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/static@sha256:bb96fe6ad4172b9be05bffc1489ad993ea432005198b2b9fa3c929e29d465d11
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/static@sha256:0f40595d20a122d2b844e6b8d35d78b9da899eb75398b95ee73052bc8f2b9694
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/static@sha256:d77ffa515aeb5c46deef38916da80239abf76eaebf6d1b3041a306d317dc87c0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/static@sha256:3c9735ca71fb17f9f25183e6d9843e21a778ba9b965655fc689c8f2fa0fa4866
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/static@sha256:f4d5be7cb84d43bca189ff786e4be70b567afe0c289c54a57545d3aeaa98ca17
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/static@sha256:82ce44920f4cab511b63c845f949c7574aef62596a01d2d81351ccf725e60400
SPDX SBOMhttps://spdx.dev/Documentdhi.io/static@sha256:90d5b20cc7805ece512a6ae08e58e22845c430d9f7c1ccc8cdd13134d2dd8371