Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.1-alpine-dev, 1.1-alpine3.24-dev, 1.1.8-alpine-dev, 1.1.8-alpine3.24-dev

Index digest:

sha256:23e59d7bd7f7adbd994cf7271ffb86ff98db75fcda347a36d4b785ff88d1d56a

Manifest digest:

sha256:d263c9b9d328dfb81103a488fb9cda4f951363f13aa5922cb20d81ea0c2e6933

Size

31.96 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:2cd6b4d49bdf24a76f2f8204982bda3f04317ee20c8a8891230d1d1a1f950289
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:0bd40bb69ad35c420e607ca35a126ea6c5d9507499cd906e529caa3a1b0c85b0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:02bdad7a36621d89decc791be39ba9167363a53cde3d751266afe269ecd19052
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:f87cd5f56e9255c90004a85682ba6c436421091cf38ddd3d525077e355c92f4e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:f1188c2b7c813800122f43239974adedbd46b99c71353c68676885cdb03a6d6f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:6e9be9d2dd4dcf69bf4839ca3a08f54829d614dcebfeb963c3d8de9dcb5e0e23
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:0d458adeb64fcd8274f1c2807ccd423ba049a39f7beea07f5e2e738b06598466
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:e33c3ff2b1cccb90629dd1cc69b7fe2d60eb6810f668aff12c3270caba244b6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:3fced61d6eaccf133de618036e28120b01345e8786d94c0a8619a335efded412
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:070f82a30a4de7917de031de2a4c3cfa7f5be41f7c7ffb6d8716f55377f0d675
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:ee5a1158b368f1b64b619d5f11161bdf916312f91d6e430c93ebe61dd6badf5d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:1aa9cbd07a3c45f9e40bd7f5886e63df1fe066b85aee03e44c02b7f8820f236a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:60fed22c05b04a774f438f0d43bfd3f438d18eb262cb39c01cf4f5fca636c5cd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:6e6b1a62c27936550532220f818b62e1de8be5dedc4b8b489813331df12b6c63
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:edc12b5b99e7cbbaa79b123c3d31fb8d2a70c8078d56ccf796213243342c569b