dhi.io/authservice
1-debian-fips, 1-debian13-fips, 1-fips, 1.1-debian-fips, 1.1-debian13-fips, 1.1-fips, 1.1.8-debian-fips, 1.1.8-debian13-fips, 1.1.8-fips
sha256:fbaf4226a310bdf74303a1888949fc01d6e2adf4a96ae177066a0122a401810e
Manifest digest:sha256:04af3f07ca8dd09bea31f4302062f33c222221b410ea99a7ce6ee23e93a74188
Size
22.78 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:b397eade8aa7d25bb958c20b7f82a6afa698c3301f043548049c00d3017b68d2 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:e0c7dcd475c0e9db127d44b3b03b6b9171ca2b64a5893cd71ce54d86eb615da0 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:879170171a498f6958611c26e17178523bcb85be78bfca1d6d51832e7fd9befb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:e5364d0315094741c9264308fbc877a1b07adad277bb739576d26a21f1789188 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:502c9e6c2240bf83cd79e328ab8e32f244f0a6419cffe138105cefdbe7d6d434 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:1f7ac2c5f65a35cb4b762f2fe55e835576c329f4a93106273c53eeed2d4cd545 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:577334e28454fe7e3bd051d108e18899b12ed710563791d2c7385cec763ac1ff |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:dd29ca2dbfc3d5f4256de06e4379925e58e0701ed402328a45a081ca65d536ad |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:787a362f8870bcd0b0b8239b9e832db9f8415313a867d03ec53352e3f78a1bc8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:21c0652b1a9642c9f4096991216f88d02142d22ab7110d129ebec8e4ac7dde5a |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:cafa667a4fab5db3e077bc7e3ddf528e25307e2fd7933d050848c0bd6e522383 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:7c4bf5167c9e9651b330aa6df8c174ab7f4cb4d7179021605530eb64c0ea2c3b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:3583e1100b610bdbfe355fdddd653a358e33399d6b43f1c68e84882b48e71d6e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:fef606cfde823eb2494e815d3b3039a9cf88450d1d91f4efcfdee7a5650786c2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:f7a918a06a213435f6f45bbd67f9a07a8e782f2677d14cb24dab0fca8b784703 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:0e0eaaa3724e259cc9775c5c617113897ce60767217520046c52e2df2b99110a |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:f1ef01938c2833b621fd89c824e67b7a581e537e5a1dc82778dbdbc9648d9593 |