Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips, 7-debian13-fips, 7-fips, 7.6-debian-fips, 7.6-debian13-fips, 7.6-fips, 7.6.5-debian-fips, 7.6.5-debian13-fips, 7.6.5-fips

Index digest:

sha256:46891698333714bb92d5c94614b57c6fb02cf20a1824a30a1d6cec748e0dd840

Manifest digest:

sha256:5a2f3d3c6d87d85f0cbeb99671b22ec7b716c55a841925a58afc05fdecba6f14

Size

59.57 MB

Last pushed

14 hours ago

Vulnerabilities

1
15
16
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:3d96bf70dc2b2f80fc03d920814a149faceebbb8463031216ad330d87fa6bd57
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:00ff96589a6292a10383dedca07768a44aaf240446281efcdd33a70458f5321e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:38462e286bebac2830168fa4360695f60b039b8aaf306314a4b82e14d0393999
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:fbd0b8d630e4fa8ea50ec9c829157ad19fef24db1f19dfd7e32f2a6b8c64cf1a
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:98c29f73bae4e3c748f1e1933484d49b95335281c6081534554a7efbb726dffb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:bfa9de31e7014a0ac6aedc31bd9e611c8353863cef3fc53ad22274796d9c76e0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:9bf28e35b71383326157585bc4eb511f52b2276514a09a4782ad038478fe0695
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:827b26a3fd5afb9eb9be02c8e70caef4168dd659980af60b2b6fc12746f1fc49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:554c0696209e1a662fb5594d0a24b4dd28d44edcd1e294fbe738bedd1ce5c3ac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:b160e852400cde6f4e9a17b4e378c3ea7c9075adcb0e9ccdaf3773b009de5c26
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:38a9d94bb43c23a3369e9bfe7fd48de87245755896068bcdccd90558faca1f00
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:1096ae1214a31f74c57d20b9f2d6ecaba1305a87f9d20f34f56a1dcf4b52c7bb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:c24b6354cfe4ac84b36ac5e0d7ef9ac41c5276bb51a9caea23f16e347b06a7c6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:203ee15cc86060624cca7728b6311a5f3f769f30225ecc84fe654ea3cec32e8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:d5fce20d3bc564872f5326c639deb4710eada19af1dfba9c90e631dfe9bff0a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:e24a162366f1341fcaae1387688ff94c815e5efe530e99982aa2da9762f0f189
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:94da99df23cb5e555b947e76e5555f9b8883e61d8040fd0a414ccf6abb444af8