Sign inSign up
Unleash

dhi.io/unleash

unleash 8.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips-dev, 8-debian13-fips-dev, 8-fips-dev, 8.2-debian-fips-dev, 8.2-debian13-fips-dev, 8.2-fips-dev, 8.2.0-debian-fips-dev, 8.2.0-debian13-fips-dev, 8.2.0-fips-dev

Index digest:

sha256:42dab141f9a4b48ea66ff8d591ae08b97bafd22b542d7f20eb620b682a5c1ddb

Manifest digest:

sha256:7a89bf134f7345ca4f814b2c036fcb2b9e3190582d5ffdb4a067c36185710a73

Size

82.71 MB

Last pushed

13 hours ago

Vulnerabilities

3
12
9
1
2

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:8-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:8-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:edafbb7d142a6be036bb59f69ab05e92bfe8bc6c4977ab7c497a1343f3723c39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:d33ed19bad235f3fd486e14a48fc22e0e16d45059bd3004cea1aa5a3e9bc2d99
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:c34cc99f4722ff1e90d60cd3198406f4aa18475d4bcd3443a78b7758e97bdec0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:696662ec601bc94d0c25802fb15db2da0665dc1ed4cd5c0b2e9c2a775c7d1740
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:6d42fe77b6538c08fdb9e6ac43a5f6efc4cc352da51ec6f4dcd2b387ecd2bd14
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:f2cde3e0a66228bf12bd305236cb2994cf555620f60d782332c24355eac81936
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:47f7f0db6daa0adfd7d770ce0c6a3b97c4a63cd6bc2bf2ccc9c51046d8211792
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:75b3e4cbe345bae7bff4eb81eaec16c00b899e1071303c1329ca8e65e224acfb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:5e283b21fc592d2bb03ee5149080a6a4b2b6b7b2f5f846c3af137de16144459f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:dd87f794dd8da9ab0151eaa765982047688d4d0a88a864f9be4e9514e3f47541
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:e39b55bcd51b054831a4ac7b1e0708be93b024faccfae31a047152603f317c4d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:10cc3781627eba3ebfe1903722f62103f721bedc2d4e11a1c5070d9a2de405b1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:78f4e2fd19c001d0a9910cc439ea54be779a79b25c5ab79e3309d02c1818b7ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:636bf868f5fa2180671a324d1bc9e3d0877762bc4c57cb6ba7c3529476c4aaa3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:0528d4b1fb24c4948d113b05e21e509fd4d498b2e2cf33c3c065c3f1f0a8f510
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:5c5eeb6cdaa39cb536231b1c141402bc4e3d3dc71d7fd615cd94b27159774e38
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:4554d8b6f3a33aa3f9a89f3f5c9bb6c8634690ae443be741232d96224fc8279a