Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:7fca83e74da4fbc30aa57d2f113a1048b7574119688977cf2f84993e27c8173d

Manifest digest:

sha256:bc4db803b107f8116b07fc03120f343c10293f5ebfdb55fd3f4db05ab591d10a

Size

52.09 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:a8cfa68d7f46fd40bb3affc0968676501acddb52cf0887cbb913f0fb46fc95b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:ad0af47845288b73eb8906d812dd4b9e41803872c8aac819018d2c2a2e03509f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:743a1611b9e230b94fe1181301b0e29cec52609ae9ef10fda151e00145ec4820
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:558aeaf60e7b2916293c963e6250ffd0305c20322a196e0e2ca5c3d0674c2d50
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:d2a38220a4854a0830cced18bfae35979ec91b5efc5663726dbc3b50cfc82220
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:e2422256b79e9f9fba140d753405e3944bc711a972e5702c915722360232e18c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:bc8c790035edaf68d6c7e72b381b03da11485cc0f95919bd89f43406632c938b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:10c05ed8bd8afbaf3d7e366413647e33cc1786eca1070b7330aacce482bc9437
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:af9b287f2d4b86b57cd96fc08509b33e3186e7a8785986ef4574537c18dc1987
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:e76006bf71a08312b00b432dd646601e87a7e2082c3a122da31ac718f7731229
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:0102b5b5e2b016b5e7d3df3971f83d732c48a108157494cc7b8dd72bac50503a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:646d71ff3d82c0d1cd248c95c642aecdf6258e544e597f5ee56e28ab48b0b24e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:b45ccae24623a3b08cf7c4eaf95d2179917057ff4bbc5e27c8ea961fcb0df11e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:26eb9f7d1f4ea31bdf1283ddfe9f0770aee4fee629aeb71b87f253187a12475e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:b77b2605819127c767ba95c9d63b96b2e852744134433e66d752decfc5de96da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:5a5754d1c12402502277fb901adce04c791835f39b4833ddc683b0cef924e066
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:1e5a8acbc7e61558105996dab520b793da2e4ff0255011cf6896fb0f5ce6663b