Sign inSign up
Debian Base

dhi.io/debian-base

Debian 13 Base (dev)

CIS
linux/amd64
debian 13
Tags:

trixie-debian13-dev, trixie-dev

Index digest:

sha256:08fdfe034cad3ad655f6afca1f51e7e0462efc87ee96621dfbf89b48261ab7b4

Manifest digest:

sha256:898db5bf3ceb4137d271d272ba2f4189fdf97b4c923eb91f21db5aba0b160eec

Size

23.58 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active until Aug 2028

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/debian-base:trixie-debian13-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/debian-base:trixie-debian13-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/debian-base@sha256:d99aa0bec09148c52f0ce51cf79a5500dd8832cf323f3d7392aedfb4c009b2ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/debian-base@sha256:6e6607eb5091b9e82cb9b45b92c52cb36ff3f567b4b6324d132b94f258399c18
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/debian-base@sha256:459c5a9a8c7dbbf7c2bcdeea5b0ee9503044350bdacda057f0cc434aa38f3222
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/debian-base@sha256:6078d782c6e1924744dc124ff20224b68f06c9bd800295ad0e2977a8fc5f71f4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/debian-base@sha256:de496db30c95aaf82bb8f754d37e81923b960c8b3bdf7560a918a472260407b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/debian-base@sha256:c980c19045de536705531344ac46aebae4bd4b15343cd6f5ead12d23bdec61be
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/debian-base@sha256:59e6a38e905024d0a04f2575f4e9d2dd4d31e7a0371fe027066c3cb89940119b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/debian-base@sha256:103963a062bace1327c5ef5061845b389d8dbdd09ec706f9846c4400918210f1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/debian-base@sha256:b0e6f08f1de981d168da97ca189a5a2fee7a1e373124b04565e89b24c7cfd53e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/debian-base@sha256:47a5178f10b39873518a1f1a65b2d33d984ab9e3bcec9b6dd99ea06fd52d0249
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/debian-base@sha256:96394d07933a4795cb00f007d554bf12901f66d66de355470e6e8956b95a7eb5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/debian-base@sha256:503a799f6cc8c02fa0be089889cb25af18f51ee96ca99b18a8f219253ad77260
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/debian-base@sha256:64be0100be60599f68c8aeeaba8af5f6147aed7176e933fb41d7d3214b4a35d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/debian-base@sha256:cf761fa0c5e4e5fff86bf848694411d3a85c1270b059ec47aa1b8370edf75627
SPDX SBOMhttps://spdx.dev/Documentdhi.io/debian-base@sha256:e8b3f6a3a7360287394c4b268d7bfe662f200c8e672ee55ce12adc1d9afdf4fc