dhi.io/dex
2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13
sha256:ea054466320916346e97345f6e67a347395ee065011b891f414661c64ab9c2e4
Manifest digest:sha256:db4bba5d6198c5c2617cf4b34582d37863fb59f0c1b7b6b43680895f232b992f
Size
41.14 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dex:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dex@sha256:84d519fdc39bf454691a428616f955b053c17477907937d6a592d927123c4ba1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dex@sha256:5475d110baaa9d3251fb8bb28e30d0bd974c3ee61cbe9c4f8f4af23c0567fbf1 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dex@sha256:168945700237139c8163e1497c741a4b855e3642bd9bfde397fb09632bf752b1 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dex@sha256:cda9ab2dc8a6e2e94b35dc8958ac34d322d9ad6edca8785215af3e9267c2243f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dex@sha256:bfdb80821476a281780eafcb800b979430c999621bbb882843b081339bdbedbc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dex@sha256:11eeb9fa2ee8be4ec3df619d3ed7c3f67403f9cbad7f827d72fde5ae419c0448 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dex@sha256:c2c43f9dc50c18937eed5ee0c1efe1b1d70656b9d42dbfc36a35e00acdf98985 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dex@sha256:499c40056470aa1264c12ced85c7216ebc18b58611eb4ff26b6f8efee856f501 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dex@sha256:1ea1a1d0b9afad563ef903281a99688e21d3d07ef7517f1553669359a5962689 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dex@sha256:c9c2a0f5f5da80f275be74dfe1a14eb826fc6c2132993cc832147a88728fd5ab |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dex@sha256:1cff7ae387e3dae87eb8fb88b1ad9632954c5ac1c9cb4deff89db87e5af0e131 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dex@sha256:3d8ae46ad765486699a21c3b0415b7a788fc28929a67d4f013554db5f528db1c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dex@sha256:efca377ffc64c219491a023adf021540e82cae96ee739090e14cc5ab52d5d218 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dex@sha256:adf05a48856d69ef7e64af69adffbf6c8055ac8b80ddcb7aba8d7e9f7957b611 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dex@sha256:1e4011f56bd24a3532d4dd45caad9d2f1ccb22e686a8109de3f1821b2b443d48 |