Sign inSign up
Unleash

dhi.io/unleash

unleash 8.x

CIS
linux/amd64
debian 13
Tags:

8, 8-debian, 8-debian13, 8.2, 8.2-debian, 8.2-debian13, 8.2.0, 8.2.0-debian, 8.2.0-debian13

Index digest:

sha256:ef08ce7f4305cca172a32eeba4b9d96e29c6a66a8b977e5bc5c071964852f614

Manifest digest:

sha256:d7cf62a0479d8c3eff08c920519e9d4567b52c0f072d9f1966a7ddc6a8a2bd18

Size

63.05 MB

Last pushed

4 days ago

Vulnerabilities

1
9
9
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/unleash:8

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/unleash:8 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/unleash@sha256:8c935050ef57c6d36468c52b34cc4f045e3367f9ff641ae318f55d3b1c2d67ab
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/unleash@sha256:a6d34fba4d9b3fd8a5614b9a1e9b3eedd5fa3dc01afede5e654913fe3142e9d5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/unleash@sha256:633da0468190f056d826a0965be0c5b6b92bfcf5740a78f3f8b0d587af30979b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/unleash@sha256:df720b729492c3ef3863969b6494496a526e190b659a58df775e0f15b7563145
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/unleash@sha256:2502d3ca9e0036b4a88cad936bc31f5684dbb465d84fe1ad9407dd5920f1ad0d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/unleash@sha256:c1c93df1e0377315a9d6050cd30d57e7428b758cad417d4e5320d988c038f781
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/unleash@sha256:6cff2c7649206b3dfb7d41f0d1b99c1a898ef7379de7c3391af5955022f2ec57
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/unleash@sha256:27583f174521da732fd63bacae843198e31bc4515d147f0d38df7bc1e15def97
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/unleash@sha256:c34ebb617ad5f275cba9717a11470299851e0d0854bfd68f9bfd35e9092f9caa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/unleash@sha256:d6757eda9c278b2fd96bf385f7fef9d010d25f7790032dac4ebae3f30c05377c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/unleash@sha256:70e5b7d9561c45f5508a7c7a0dfaaeae95c317a131c0fba1f782844140920ada
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/unleash@sha256:95025859034447d82566d7bcf609b9c051fce723867da9119c8d9ff455656df1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/unleash@sha256:b1ce183acbd1bf895422645435adfb69735fb4352d7fd544cbb2726be1bf8e76
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/unleash@sha256:6843692abda0ddc4b1bb48672ca505d069c9195051b1979468857d70b8019d19
SPDX SBOMhttps://spdx.dev/Documentdhi.io/unleash@sha256:568af9d2787503230442295e5187619f09e866d23176287f26c8ca4d19fc84be