dhi.io/spicedb-operator
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.27-debian-fips-dev, 1.27-debian13-fips-dev, 1.27-fips-dev, 1.27.0-debian-fips-dev, 1.27.0-debian13-fips-dev, 1.27.0-fips-dev
sha256:77a494654c378eb62e6aaba4117286d773f8e2da8a96384eb41f15748dbcff7d
Manifest digest:sha256:4465f1fb4696403391938575ed2aaa814c4e6a51ba123d8f55ac7350948367df
Size
58.70 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb-operator:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb-operator:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb-operator@sha256:02b1849d38f87ac28889898646765be18b912f7b6f2cd3df8d41bbb3cf65d41a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb-operator@sha256:3c187b42c9ae8743ed50f46a508751ad7c78af949b102c9fffd35b2ef094dd56 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/spicedb-operator@sha256:2b3e0ec59b27e2c709e9e109bbdc45f1a083d9fba20e7c8b6c9c7ec24b7e9b7d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb-operator@sha256:4fec6a1be02e77f189e50015ee8fb87c0181bdf22e869f6975252f8ebf9cb4b8 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/spicedb-operator@sha256:256b30c63275306dd1c81c07fe90c8f571cd690efbb8c2ca457a4c5ea12ba278 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb-operator@sha256:53f23868d9c2d8fbcfeb21d2381b30c6817e7bce0663fe0e695735f70a8bfb48 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb-operator@sha256:85ec01be7198924604a1b1356b97ac5420e2906254e8ee10dd094d87330b9f75 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb-operator@sha256:04dbe3efb6ca1a5e85bf56673740e2a87c7a57d9c98127ae8bc51440ccd41cfc |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb-operator@sha256:927a2591baaa9ab0475b87e1765871c4405cf31267e4f6f5183a3f094a83bde6 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb-operator@sha256:7ffc6ba3176fafa6c8be500351b1564dd75a60a1eaa70bd0f986a2d06da9b0a3 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb-operator@sha256:fbbbe3a8ed05bb06705ef19b5b2b33867e470540ccfd436ccd3ddbd6216b0d16 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb-operator@sha256:f10d52230be6f5c4022cac0b15b1592bd7e7afad8e41cb90dd0e52051c0e7f82 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb-operator@sha256:512f288095f8192f6de2f5f783ebb94f894298ec0fbc625d72d834f94bd9add6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb-operator@sha256:d16a92e5a0a6b243b2dad32d394e43f14c3ce3325a0fd82962f1729e7b65b000 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb-operator@sha256:4f0619aeee6c632ae0433c79fa8bbf015755254e9ef604f312d8ea4e9479cff8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spicedb-operator@sha256:7dbe9e013aa318ddb68743d158b4944553ec72986fd9c8c48774f56a398c8b17 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb-operator@sha256:a0d8d88a50bdf9abdb70ca130cbdb1f980551ae7d439610c260f981bd90905ae |