Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.15-debian-fips, 1.15-debian13-fips, 1.15-fips, 1.15.3-debian-fips, 1.15.3-debian13-fips, 1.15.3-fips

Index digest:

sha256:17c88de94fd3c93085488e3a00cbf6a50fa4f8ebc7ae191ec7479e3fcba2ae43

Manifest digest:

sha256:8c2521c496352fd29f386cc77cda601161f1885b6a2e3c4e50827b174e1dbd5c

Size

44.20 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:fc7440e5bb5b5e5d29d9303c24cbf4db54879af6c789405e35ee9bf7baf275df
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:52c319fc73ae21b06b8d77fa898b65f6880e44c14f49611c3b4d8d9d61965418
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-server@sha256:523ecb50d416162f2639cc88b5099c50ad2ac662c5957ac6b8fb8df0895029cf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:590f3d576d038a7f7ea6d2aabee874ecdf390c51c2c3d7fc3c751f9a34c1eaee
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-server@sha256:9d1f4a78c00e7c18bea87d71fc8551d251d821991c8145fa91ff7047ef0d4b7f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:d4f717d522ba3be9112c743206d7834f1036b75c8ec06242ecf0b5d25a42f2bc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:7406d1ce4507c912b2a4226b77fcea839c42b317595bff50fd09b04cf2be6aa4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:acb40fc43fea4473fc6caaad1ff483f3d11eb9183e9be9952ab8ed3ca34b2919
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:afa44129fa78a81bf0a366ddd36b203dc8e2351f493a4de65ee6fe755450c138
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:c57be2926152efc9f71e9aee7d6071d89feded457db538f1202b44b1a04e0898
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:cb0c041e1f58b694ea5dac3045dce3d8529fa4cb8075dfb2d951722a616a6f63
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:a9d4aad08c1857ad72b0816bf693ba1bdb3b908a32d1aa2ff86c58b91c9efc20
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:9175d4b4705a44e7632436e344eea2f4a02fceb88d7a6b91a027371a3d9ea33e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:168b79ee6dc3df86fa4c9d7271dfdf1b845c6e92c8ce99c6f6b948724d603af5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:842968361d84116d6f1eb3a1902330f16fb9af1f3af11359ea6c199afb81172b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:d6371b40aaad1b8a7038e428fcbfb3f831204ab31f06b6e074a1c00ce0aeca52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:ef65e674e675b7b2e0561dcbcdcfa5650af7ba3af1026bab5de3163c38fcd65a