Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.8-alpine-fips-dev, 1.1.8-alpine3.24-fips-dev

Index digest:

sha256:17059b8a45bc2121a70abe665862ad000507ca8961cfbc8e6264072b096e2f9f

Manifest digest:

sha256:d2ea4a78ec48a204a587d153b4f0f00d5317c44db3fb6bdc3e68e9b64b8cd08e

Size

32.79 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:211b59a611af31697fb41ccd11ba22a843e67460e87d5ec8387c721b0b206423
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:f47fca91edfa4f4437d4753ef6626837755e094974ae8d1f1a3047506e2c403c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:bf4c2f547a7f3e67494a332e2afdb04548a98bfe0f9ccee492ee51a6e82da8ed
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:ff037433d89e0a9515d0b0f0b9099b50be5df6953908e1622273c3343acb39de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:dbad3f512a7ab63c84936fb7e4f9febb5ffb8fea05d64748105d0e0efeb900ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:623130659a688e815d0f209013f5869b88a07ef6e1d64fb5fd18ad1b3cd55d6f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:728fb478391e4c4a1cbc6cf8d11907a14f70b558b4b4b61f552ace4fc90c244f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:abe6c646118990c8f629969b0c82c8945e9c83f971674df6be0d2a7174ead0e6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:b56ed0d43c41e3e1fdb960ccf573761657a32918cec2526553481121b6c7a262
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:1fc92cda49614b53e7ac89bbd7f231e8b8591dd763edcf4fd0080a3f88e2f1eb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:f125dfa6073070e444185cacf7c4b3051c8a626f548742b0636ab2c6baf13c47
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:169f5e274bc55eaf1ad3a71b9120ee082abee300b5a5000ea1844ea50e1a3c24
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:b47b1f1109f719eaf15fe5ed2bbe44e484bf19da5a927a71844af17399551df6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:2e66ef536d98f31622d0c1040c40463f197d290c3e32620113d9ed6713c904f5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:c7173405039497d3cc8c5e1dac105af2fc24d5e08b508e0526db3dfdd9ef0b65
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:86d4d36f6373bc63c3ad9ba204036cf9af71c1e3e201813b96293ca0c4fe1e07
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:d85fd072e356c71e9379105420c6ee09552f2b5895820e0e6ae0c3d6c76545af