Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.1-alpine, 1.1-alpine3.24, 1.1.8-alpine, 1.1.8-alpine3.24

Index digest:

sha256:a8d1d33998e92994397484c5641c66caa72f9103c98dfba1b135ac3158adbbe0

Manifest digest:

sha256:71fccda974735be49c8258a8d186e00697ec093920b1da921bbd948a950e50f4

Size

14.29 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:73f279b11308834faa6a0f2836d7f270c44533d97c6127ae84d3cb73f306c39d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:419c1aaa2d9892994dc2d91ffde0adebd5f395c7d260b783d28bc009b3ac235c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:dd385f14e9db8db21d4df0c3d10be523633c82f72ea7cb620677a8e50a3570ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:377752ce79b429b0e9c1b19235e55bbfae539f10b06d6d7049777644496bd338
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:d21cc8d0294e12eed7b98eee3591b5666883dc887d13f5dcf5317b97e8f87aff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:0688e3b0fc294b277c3f2a31acca0ba68fa3ed8813098a2bf195b502fb5d9a68
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:b59663f84bacfa98594ed4034d84894cb53d75091b1b5508792515059ce05c1a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:d5720a9db319dbee4a0776a55aa2a35315b7e669c0fd461681b403bb01ddf7a8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:0d04739fce27b669fbe0dd32b8dbae8ebc978a8b1fbfe5f2857e8f8fc0b5c737
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:4ea6b0551755b80fe704f59bb7d50360460755747682b3b8cf344b580ea86d46
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:23a81948e9321fa490dfd94bb2a381338b0cfd9b62337391b2eaedfaff7fa7d2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:6dc6a841fb7d009ff4252ce342a37f2edcab42c94b42e297786440293db9eb2a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:efe491225a862025f8b8cead6ccc90c240a3546b0656b51795e29adddaa5c8a3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:e6529e04ec28db7fd79baa271462ca8a215c9842495b4ddb390a5066f3c345ae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:fad1f67250afc7bcfa9145eb5223a3b633ffa35131492fcb2652daa5677735e9