dhi.io/authservice
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev
sha256:95536331d72690486b721ee8bd21c0c90ae13bd305dc6b759e7679fa0000e8e2
Manifest digest:sha256:c1a0dc37741d483237dc4ef5921be04f08d290ba069d16cf8d4f79163cb4c6b8
Size
52.08 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:0cfd2c2c78ccd784b7b73a8f0a7d153c5d94cf128321dfc60e44b2949a1ed93b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:1eef09de9eb5cf163bcca19cb147034e8b778b6366021f4d9cbb7d8cddcaf2a4 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:f8203808a60c01948ee09843ffbe54e1762954c418a465834e0831eda26c26e3 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:d8450c81a5e2940b869444d9009106160fa4aef055374ee9008cc5f3fb45f722 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:dacbeaf5d5f1f7f08a8768392bc5dcce6090a38a87fc342f18d8caec8e3a95b6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:d4eab9f8947850dce8c3c4e7218308904a89fb746be5e1ccbc7362d606604f26 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:db927f6333740ab12a11c92cafd04a9e5530bf3ce9d6f9409af48e524c55811d |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:8ba96b80ff116ddcf49bef41bc318222e759f48a9d744698c4a8e4c5305f1157 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:f4063f67da9e94b51fc6e46450f7f764175c04f6c078c58957887af963d68ab4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:a221e0b0a7b8acdfc50d4e94f8ba8e0875b36d2c04f55e132977b6adb6305571 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:d79b4e1fd363cad6990c229b3b8a830bb2e1dd755718754075cb3bde3ceb88f2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:0e68d32bcbd4484d79a46980a3c5b1ed68046ac1b9498f2016848ba383f3651d |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:3f0aab187b2a8ebabcc32c84e550828a44ab17be904002c0bfb229fab33df464 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:0c52d82e9cab086e1a99767c50fc1d06ba369de01ec395821e131dc584657429 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:b4cee8b566c9e61397f4c0eb86c2a2a31352699e8f7bab74c5fdaaba8a5eb7d9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:21b4bf4fb93b0e1e504682c3ff09b75413451a26d197e027f213ee0e0408d932 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:cf4083bf0012128cecb9eee41d2fa3dfa47b0f5ee6d6c046ec3a3c8f1f426ab6 |