dhi.io/authservice
1-alpine-fips, 1-alpine3.24-fips, 1.1-alpine-fips, 1.1-alpine3.24-fips, 1.1.8-alpine-fips, 1.1.8-alpine3.24-fips
sha256:b9368999cb1ec3c173b82070e267aeef53211695588740126cabd5d4c7def6ab
Manifest digest:sha256:2de49d3e40494826501f42b8f1579b5399c2022c43f929da4dcbf21d6100ed75
Size
17.71 MB
Last pushed
5 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:98d0f21dc3962eff2ad324246b82c5daa211fe3abe5d36d5289319c227504a4e |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:5cef555a393a4027993b003dd440cc85581a814a0592b8274eaa336385329a91 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:e9db819d3032b0b959be344dd68fd7c64c2d61f0732e589d973d9e63c6569c6b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:d8968e85be5c0a9fdb6adb14af6dac3c46eb0a123c712b6a20a37fbad2906df4 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:5622c547f61abe8dfd943a865c4456dedb1471714d97342199e71f4e22b00805 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:07193818e757c818401df7c0afad29013a98304ed4456b1822c85e793bc48b81 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:91d9a90af3eeb0d18023913e4bd7d0d456e7a2bdba5c8afe4d9cacf38ac7054c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:def13f1c2f076812feb8105a521777e1efb0072d1d2d03cfb76dc610ae01792e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:d8da7a2a3e237454c561ca83d255f87985803406e0bd942fcb49df63203d7836 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:10bafa5f9d43ea3010659c7e4110da2fe417281dec09538887c6f8f4a0158a39 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:842325483c0f6341e7dd2715677efe31816609734ec7b57a1eca3665680421e2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:1a66ebd59d7068a183b100fa287cad68e67eab669c51f6b63fda6a04630f2c49 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:0d424ab32fedde82abba6a515a36024b1a8a299740b499dca62af29e0cafc5e3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:5fcad7480af3fa860b460be6fa361a27d9caab1c2d16cf211692bfbebefb0326 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:24650ac06284949797429bbf596cecd60afab75d19a2be020fc48de7fd21de47 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:d02fa009c8a5fc986ae4c96e6d2d0a10e42cf35800d50fe0ea101eb4294e7561 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:810a8f276850b12d1a85f9ea4390e0e4bfd0be99f357e1b29d1dc4ba1baeb50b |