dhi.io/authservice
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev
sha256:3ce0bb54c44a3a57642f00b7eff814686914dc2a656f0ffa0ea8e5f5a0047923
Manifest digest:sha256:296f429a8c4b2531a5a76c6427ad072f1a70502278918226d96a3eb355cb6edd
Size
52.08 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:f5b94d23aa1972542f30da8d05872d5888a5e4b0dc7106dabb72093f8fab5537 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:60a15fe34f437e90f11cbe5af8761fb963727788d6bd3da718096a1ba2598469 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:8f63b93e9b7b1cdb1ec996cec51b14c96139e08e411f4839bc9ce8683d51175b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:a77017eb805639eb502a99ec719ef9f6c11b0fb2261e959c2756da8d05d97e5f |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:e82cee69715bc72bf8498e0c9bebc031151ebff234694e57d99b75718219e1b6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:8961ce2cf5f9382074dc5af66e04be3c966d73047e5a4d9f402540355c4ebcb2 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:7678814f5b1c1d43f865b89f619816ba9600d7f977f17c2e1a0a0b901a68d8fb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:a0993467619fb7ea2280ad74a8c5df9a89d8eb0f77519cec260c0d3ea3ac9d44 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:2c9f53f3d52f20e878ae7ae2ed224cee4c32367cd7fa2e4920f3967557698191 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:855a0df182d350a565ccd1219adf6ae4859451d78cf74da897890dd504c46633 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:3aa8228d17cfe0f60e30527fd6aebc9f850037a44992df680eea0c92976b642d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:7b7724cceddaa669b272796bd058cdece7fe8d9924909b2fc8dc39a7df32fdc6 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:f86c6f96bf0ad71142ab5180494b73930176fef8b3784fe8eb022f514de64639 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:d133c5c93171c5f4609d4aa0e067237ec1d8643b01862dfaf0443217bd65baa1 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:192bda469101c25470f7d9de14448744e54e4bede21a5f4075fd9acb43c561a9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:002c4357fe6a621d02b17bbf0109de78ae6beebb98130a6d6f034c78e7ddd145 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:2d11922485f8c47dfa5f6f5d3ba87764389d06de8c3271fc3bb4c14c6c884204 |