Sign inSign up
Dex

dhi.io/dex

Dex 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.45-debian-fips, 2.45-debian13-fips, 2.45-fips, 2.45.1-debian-fips, 2.45.1-debian13-fips, 2.45.1-fips

Index digest:

sha256:25fd943edcb47eda61d0ddbaa1feafa186f60ff115873b5337e8a4e60ac3d0d2

Manifest digest:

sha256:a3232b1309bbc2215f54b1cbadaf5db09ded3875f4e3c0c0ff33002c0d187df1

Size

46.38 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:1b44fb77549f9f3d226a3640c6120e37decc7f936379be44855e53b53c4e58ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:737c0df910e6b15804ba138abf9a50219ec6363b3d3f52e60fe0cde0125890b8
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dex@sha256:ba695429362c1d90a9dcdc4f9c62f500c214e35d0a68ae25f361f377a0780f7d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:aec29cb1b57e1b5fe7201a48c9a23f2889f69cb3ec1cfedb98e7634706b8d61f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dex@sha256:6bb82b5121798950a0e7daa82040470ee095a8eafa41e7af00ff8be91a77530d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:c91b627fc9b540690b506f938fd6fd914f7566c1d730ccb295e3e936aedf4e16
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:cac538323533818b9113c307d158b1352503c4940d33791942aa1355c4fa375f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:7721e4fbce384301a535cecfbef06d8b4f8e16c0d7f8c1c70cb969c22dd5dfad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:e2cb1878356c51e25da8907363940f90860b09f570eeaa15babba80650a14d8d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:68f468cf4413facc1f0151efd00b16f597fb19c81e6a695924f8aabffcba649e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:87fe560b9fb2ae1f857ded79eb4d24976f568e3c094089cbf284bd7294600acb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:e5d1a8d2d147a79b249f5638874673296e890356d21158ed3d7098aa9a50e847
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:692eeb47edf0d960ea032f69d47b5487a662055d3d34dfe0d60449c1b1bdf729
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:2e823ef509cb18a3d3f7b5e71a7501aca17f60c6a2cb3b5f00b0a4c485ac16b6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:109b773b13d031b8f469433935071c732adc2dbb4412f781ec263b2914f79a69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:7cd2c73c312f1272836bee76446165336600be649b348165942dfcb386a071b8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:e626c60eacb746255b5d8506dcc162985fd7bb57240599ec9650772d3fa9c06a