Sign inSign up
Unleash

dhi.io/unleash

unleash 8.x (dev)

CIS
linux/amd64
debian 13
Tags:

8-debian-dev, 8-debian13-dev, 8-dev, 8.2-debian-dev, 8.2-debian13-dev, 8.2-dev, 8.2.0-debian-dev, 8.2.0-debian13-dev, 8.2.0-dev

Index digest:

sha256:a835b998be13e78a83b112edf18cc1f8288f5ac2db19363e2f2c2714404932dd

Manifest digest:

sha256:e21742e818c4898774401bc4e4bb8d9f33555fb0debca4d0cb7005de1297c508

Size

81.99 MB

Last pushed

14 hours ago

Vulnerabilities

3
12
9
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:8-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:8-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:54c4d0ced6ef5dcf3174402c919cde135bbba5dd1b9effe69264eebf59cf43a9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:5742c944d6344a2e4f1853caab941c6bbbca34936d241a22096e8b8fe82f6247
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:648fb6ae8e5f455752fc79eb2caca8bb71b3c4b130029173dbc24b192765214c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:cda4b85619df7e86a6af46231f83d9e7935169735789a39ca88cbcf2536a87be
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:9227beb6e36f26f29bd409b37c01a59c0cb79a570d7b30417f1fc82ff5dd938d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:5d8eed3f4a7328ab9ba7fa07c6a1e5f6cdb9ed4b957635995d018bbe2142a97c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:2523942625ec9329e72c0ce3186e7a450d12e0bb95fded9592527d1026d7c35c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:25b15c7571a1b4fd154c302a6ff876b84e24a89c6586c0565e84c1d01a2cba65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:37a05ec58142fd0a7f955fd1278a3e1b79b65a686bb81ccfd81ec76746548bf8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:066055f0cfb4328a76e70c509a6730d997856adee3cbac0cb04630818fda9380
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:5386336bc0e0c429c4b45ffb1769359ded588a0104c53df97371e153b06a813b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:0be35d67df4b6753538b976a49c0def4b1a5da861e61aba333bdce87c897e19d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:a2d97ff4e5ec0e4e0b7a1fa99e658edc5b3208a8d609432a8079d911388a1c58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:ade700f18cc13f4072db668bc55ee41f54890e07b319a6e5325129305b776b91
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:894e3021515babae113e59b089e831e60d9a6072976e2647993557fb310973a3