Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:3ce0bb54c44a3a57642f00b7eff814686914dc2a656f0ffa0ea8e5f5a0047923

Manifest digest:

sha256:296f429a8c4b2531a5a76c6427ad072f1a70502278918226d96a3eb355cb6edd

Size

52.08 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:f5b94d23aa1972542f30da8d05872d5888a5e4b0dc7106dabb72093f8fab5537
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:60a15fe34f437e90f11cbe5af8761fb963727788d6bd3da718096a1ba2598469
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:8f63b93e9b7b1cdb1ec996cec51b14c96139e08e411f4839bc9ce8683d51175b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:a77017eb805639eb502a99ec719ef9f6c11b0fb2261e959c2756da8d05d97e5f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:e82cee69715bc72bf8498e0c9bebc031151ebff234694e57d99b75718219e1b6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:8961ce2cf5f9382074dc5af66e04be3c966d73047e5a4d9f402540355c4ebcb2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:7678814f5b1c1d43f865b89f619816ba9600d7f977f17c2e1a0a0b901a68d8fb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:a0993467619fb7ea2280ad74a8c5df9a89d8eb0f77519cec260c0d3ea3ac9d44
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:2c9f53f3d52f20e878ae7ae2ed224cee4c32367cd7fa2e4920f3967557698191
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:855a0df182d350a565ccd1219adf6ae4859451d78cf74da897890dd504c46633
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:3aa8228d17cfe0f60e30527fd6aebc9f850037a44992df680eea0c92976b642d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:7b7724cceddaa669b272796bd058cdece7fe8d9924909b2fc8dc39a7df32fdc6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:f86c6f96bf0ad71142ab5180494b73930176fef8b3784fe8eb022f514de64639
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:d133c5c93171c5f4609d4aa0e067237ec1d8643b01862dfaf0443217bd65baa1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:192bda469101c25470f7d9de14448744e54e4bede21a5f4075fd9acb43c561a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:002c4357fe6a621d02b17bbf0109de78ae6beebb98130a6d6f034c78e7ddd145
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:2d11922485f8c47dfa5f6f5d3ba87764389d06de8c3271fc3bb4c14c6c884204