Sign inSign up
Unleash

dhi.io/unleash

unleash 8.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

8-debian-fips, 8-debian13-fips, 8-fips, 8.2-debian-fips, 8.2-debian13-fips, 8.2-fips, 8.2.0-debian-fips, 8.2.0-debian13-fips, 8.2.0-fips

Index digest:

sha256:a2aa2bf7bccb811d3cda14ec4f88577ff4e21d3717ff43901b5b4da4db75398f

Manifest digest:

sha256:661050d8290dc83c76a291846c7b7e9850080d4f8f340d9706a6e45f921d9dec

Size

63.83 MB

Last pushed

4 days ago

Vulnerabilities

1
9
9
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:8-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:8-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:49e43b6e548701cf52fa2a80f8c94687de0dfd1bcc2a4002df3e9e1d0d30e875
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:a08f5a4afa3c2ee5029261c71243c471639c519690429e38d79a86943ed87d3c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/unleash@sha256:6813f98504aeb9192a0c7ba4b2ce57b4b186413c087edfbd32eb2342e7dbcad5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:a4736cf9b07a3aeee3a084ef62cf86b717d4cefd9d8cef18d8d43a35f8dfe73f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/unleash@sha256:f3db66b2d259013c4fd367505443913de6d81c0bdad7cdf88dfb16cadea6341c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:88f2520bcec6dcd7703b24c5b70797354e78fe74b64a8f17479bf2ebce919295
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:8d5812261ca9d4dc1eccbfc36fae64293017ea4bb4ae9ee13c49bbac974f4b7d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:d20da16bc1040bd599d83a63500de983305f386bdda4f4dcf80bb210b144dc0a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:e5406f25719d6ca8f15808b582dfa9f31b9a564707915dcd0fe820b45a7c184c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:3c528f89073903de4b1ae009ea7599e1b92d8e1c5dbe0b3ce0c24e80e91c1f38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:402d5b3a2b43e8354c4e60b759b08ea032f51d4bd84c17330a7021fc455e4980
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:1fc59cc6ab199ec84a217ff5b34ed603db09276b14b278c3d4bd29ee89a23aca
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:77dd8afd3f04a70bf9a5b7e8d564090db4163c59f11def6d32a2a7f98b87dc1c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:fba2d0bc91746852c6358099e3e6bb6794ac83eeb6bd3a5f8365a1404b2d538d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:a81be730281ede5d481c07d0cd673a9631e27fd44b02c842da81fbdf63b09b28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:b6caf41333b4d53aa632a1277220995ca32e82f79745bdc553711b3422b6d8af
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:2716e7cb5fba1bc917f224eaa3a11ea384d5ccd25921a2b970beba5092c17c10