Sign inSign up
Dex

dhi.io/dex

Dex 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13

Index digest:

sha256:ea054466320916346e97345f6e67a347395ee065011b891f414661c64ab9c2e4

Manifest digest:

sha256:db4bba5d6198c5c2617cf4b34582d37863fb59f0c1b7b6b43680895f232b992f

Size

41.14 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:84d519fdc39bf454691a428616f955b053c17477907937d6a592d927123c4ba1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:5475d110baaa9d3251fb8bb28e30d0bd974c3ee61cbe9c4f8f4af23c0567fbf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:168945700237139c8163e1497c741a4b855e3642bd9bfde397fb09632bf752b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:cda9ab2dc8a6e2e94b35dc8958ac34d322d9ad6edca8785215af3e9267c2243f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:bfdb80821476a281780eafcb800b979430c999621bbb882843b081339bdbedbc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:11eeb9fa2ee8be4ec3df619d3ed7c3f67403f9cbad7f827d72fde5ae419c0448
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:c2c43f9dc50c18937eed5ee0c1efe1b1d70656b9d42dbfc36a35e00acdf98985
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:499c40056470aa1264c12ced85c7216ebc18b58611eb4ff26b6f8efee856f501
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:1ea1a1d0b9afad563ef903281a99688e21d3d07ef7517f1553669359a5962689
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:c9c2a0f5f5da80f275be74dfe1a14eb826fc6c2132993cc832147a88728fd5ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:1cff7ae387e3dae87eb8fb88b1ad9632954c5ac1c9cb4deff89db87e5af0e131
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:3d8ae46ad765486699a21c3b0415b7a788fc28929a67d4f013554db5f528db1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:efca377ffc64c219491a023adf021540e82cae96ee739090e14cc5ab52d5d218
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:adf05a48856d69ef7e64af69adffbf6c8055ac8b80ddcb7aba8d7e9f7957b611
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:1e4011f56bd24a3532d4dd45caad9d2f1ccb22e686a8109de3f1821b2b443d48