Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.6-debian-fips-dev, 7.6-debian13-fips-dev, 7.6-fips-dev, 7.6.5-debian-fips-dev, 7.6.5-debian13-fips-dev, 7.6.5-fips-dev

Index digest:

sha256:a7e15513b43a18f92ca35cfa987dcd6f01b3ac4524ee4941258c192427f16b2c

Manifest digest:

sha256:3a4e66ea092d50fb02a7d36ed80d58749154226300d3ec586b3141eafeb68afb

Size

78.44 MB

Last pushed

1 day ago

Vulnerabilities

1
16
16
2
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:da9232727c1faca465617fbf22b21864cdf38b00e28c58b5e38286c7acde204d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:9d9566c71b9471a2874d6541bfc6ba1fc74a660de45d4a00634376b1472382ff
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:3d366716f2270a52317d2fe4fc9b7293876faae8ef0dc3534a5eab82b83efa6d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:3224b6650374e9bd633198b7bbf5d384fd629c850739d6a0f78db02b931de11c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:2dab5e9ccb883901d202fef829be468d19d0f2a4120d65b97d4d7fa54e270eda
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:b0abc2f9f0869c0f1348ab978a2d03028c690fe542f206882889c77c8c796c90
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:1dfa9a2c0b2df6fe47e6dd1784d260e724efaf1a76eab59ee24ce1f5937ee5cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:22e8b3a450cf8a66a3d6116b40b2ca1c39de3db169b7a3f211c9f20283f7a89e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:65757ce60d487cf177fda271f21a15e1c18b892af8bf8701b145d68908b0537c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:0274337af4512370cb37ea7f97bc689f7cdec8fcfeefdbd58bf0dcc8b062f050
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:10d3e2d2ffc51e2f1b859f917aed6fd1e7e43ea878742054cd6c07005d5b87fc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:699e570bd85d2f2b78d35acace042328ec21d0673b0dc9ee85071ee5513f8695
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:b8b160da8f4d396b66711843455502d6749d901a5daa12a91cdb7d7b75b53174
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:7fc92a77139d30db1b5c0e4397dd7cea3912e0f369d78c9d06a3cbf716530037
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:b82352d82648527a4a504a924e96458d53206ae18b1d2c99a6675a551c3b6a34
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:3d65ec94141feeff12abdb2092f76914e3fa525ff42215330043db81ddbab7a2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:1a9c80e72709564e67570a3a2834565b4acd43d74e81b999f47d2d0f74e5f34f