Sign inSign up
Unleash

dhi.io/unleash

unleash 7.x

CIS
linux/amd64
debian 13
Tags:

7, 7-debian, 7-debian13, 7.6, 7.6-debian, 7.6-debian13, 7.6.5, 7.6.5-debian, 7.6.5-debian13

Index digest:

sha256:2ffa1a81028cb7693c09173adf637fac7dd68d22f08a8dd90ef8998ac3ea31e3

Manifest digest:

sha256:fe7ae0a0048e8f19e2b37b4930fc25c80a13c4c8cb4866efbcda049c44529480

Size

58.78 MB

Last pushed

3 days ago

Vulnerabilities

0
15
15
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:7

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:7 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:339b0adb91886a33abbb05f38fc63c094698ef5608d6ffd4def572fd5f338aa3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:aabcc1ea8c1372c829f8ba5d8422a1e8ff781150df49d2297a9b6a7a110997a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:b1d9a8da9462cd7ba2769eb6552734ff8a699bc1f42576dcf9054454499f7e96
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:5abccbd65fdab13107114805711bcf188ccb284ab081872e4ce2ee3c4e44cb2a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:21bc59a77241b981003c8ba1bb6a17ded0710f7566c1c8830a31346f98cc429c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:ec78250472cfcb55df837dd0da1e80ce4a9c7b7e372881d3135b45b1a2399791
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:c5451e4e441407be9eab38a883d0e8dbe28152b2647a8a48a51b82734ec56231
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:e99e9af720eaa4d939dada8b8c97723cfc429418d0b89c66d24eb1f57728f296
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:6e2862fa54af82e818f36390f685538070028d199be6174cfef9db189004c187
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:211fa7b20cee5ab4376f083cf016cd6d8eb9b0dcb721a9065c08b5f9aee0a38b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:50a6e642708950aa4b7501f1bf5b27484e34999e99fc8fe033bba83b66a2f715
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:96ef5b1ecb6f8de3f23fb96ad1cf5e048c4336d73af8ec37b012febdb78b648d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:a3b937d5cfa3d0dc278006e9a2fd9f591c8036741aff41a3414ff4a531b55f94
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:195bd304b693f14b71c1d0292d5c269f38425d0c135b8a1084a9eca760a3a89a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:6533b1c682761bc60885278432ac56e362d37bd8b11e4fb7de0c6fef65270f7b