Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.8-alpine-fips-dev, 1.1.8-alpine3.24-fips-dev

Index digest:

sha256:98abc4c4e2f1157d159c908640f5a8adcae68d5fd0be4175fc9d1794c8779351

Manifest digest:

sha256:da980773ac26b5b7cbe0fc3d701c445011afd76f46768dda0cadf0afafb7108e

Size

32.80 MB

Last pushed

12 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:681bee5a9693f5e0bb35af560e4c8c9f468ac46c6ad8d5854a5cb4303b244f00
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:fc4dc26d179ceee6519078c6cd4923726f012ea85bd2e96a0bb083d0f0ed9385
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:544bdd4a5af76b76df55982120e826a3d0eeaa291ee7f03b43ed914e0d677330
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:064113b70fd063c0e3919ecdcbc7fb87c3a195512524ec1e6a5b1812e4df4410
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:b7dc808c77b869ca717fb5cca681de7b87ccc6d69ce7461b34918624d1092413
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:fe98cde65ffae43d158e3cc0eb6580defb2c8efefc2f2f52d3e3195d6f05c1d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:e6e3b7805de278f4d090bd0514122205f6c120956f6890498ce03f1e75e5765a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:e6c2d3f786636f768ada2a7ae06427f5a1777240511b78bf2c84121ecd50394c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:a4d2195d7fc74939162d1eca455d1a9c711ead5d18e80a4408445b1020953107
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:21afb69f6f46026bd267584baf431b260749a5990b6e155e99da488daf3bc794
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:7891e0d8713ba061a273ecf1ea8afa246a89a86993705f630adbe7e5cf3458b2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:7e1ddbe6bd6b1024bcfbb46d718bad7578300eba71faed98333b9816638f4310
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:58a41983214bafba0f3305d1cac74a32257fb213cc783a4cd7c4e671cb01138c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:ec3a916ba9bf2d4531806fd9de818a22c864fd24e1cb17231e0a0df3a2984bd5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:bcaeb111683cd98cd213ac03e14641b6e31bc5345c0c401380739c34fe5d2476
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:d9a872a2404cf0297e3d7d5ee3f8aa429ff872ec1ccc31de9888a6eecf75021c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:ee9fdb20b694523bb5d0fe8f438d3beece92d7fd24a282c5e2db0bdbda6268f1