Sign inSign up
Dex

dhi.io/dex

Dex 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13

Index digest:

sha256:c6b6277fdb511c1ddee5b2610b84d074a3b73028e2855859cc48406a255169d3

Manifest digest:

sha256:c0666b76f6a5010bcfb856e6e5b1c717b7dc8d17abfe92373bf14a93e59b5a92

Size

41.28 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:a73af2c56e1aa311504a89f8fcdcb53ab2651158a8681fb57e01a3e3b476e70c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:0203e514f166aac1afecb0daf14f4529bebb1d300fb3d8953fc872498d221cf0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:20360b12684287a6c114d28aff34547732f9e62cd25845d579d5b0db27811bab
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:66ce86c67335ade63df0eeef3d195186d605c8c9b6aed669bf618450b92f01fc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:e53c1156c29287356e811b5f6d6f8e58ac2b5382dbabd6dab92be397bdeec47c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:3bde3802726ea8ba48681214d4868f3cfb18a2e62b3d7116c97563ae4d36a8c7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:7ac7067e6620290505f11cf9045d799d031c88f4b11fab2c31a4f857be81b33c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:3856ab1f2a571dba14c547f2eb570f60dee3a47e041571305b7fba9ae0544cf5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:0693d959da0e04390d7aa62af7cb7df7fe832c0e2fcdc2cd24c09a7be7fc1057
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:dd93fe77f048e4832ae7e10331dc1163424852497ac263931cbfe826cceb9272
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:f22ab3b651f911ecaf9157ea0840890113842e76f69a55b1f849b336f8ef89ed
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:6a960dd041ede7c8283a9392e3d0541c4ede013d5b3eca16be354ce483a11728
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:f5a8140a4daf72963452ba146c6784baef2105c8040ad4e27b04506d7539ce4e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:51a843e0345ba178d02527db09213d7e2c45412546152db43667ce94abf6a00e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:864ec8431b8b199f5ac693afbf74e2338ca2a5127e26880637309a66fa721f72