Sign inSign up
OpenFGA

dhi.io/openfga

openfga 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.22-debian-dev, 1.22-debian13-dev, 1.22-dev, 1.22.0-debian-dev, 1.22.0-debian13-dev, 1.22.0-dev

Index digest:

sha256:a5794e7ee20c959bb18b38cd8491484451837a15151b1c5383398c407b2b7b51

Manifest digest:

sha256:603fa2d7e47c6edc273bfc04e7fa7f93505aa86ae76722de58ff1e112a592d21

Size

64.90 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openfga:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openfga:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openfga@sha256:e149c8ea890fb835ceac1e92e8c18389d8c5748e60379637116c8742f58346ea
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openfga@sha256:069c9a7a582efaba8cdf21ca2f351f19cc9c764c8df67c64bf1dd229ba2f00df
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openfga@sha256:5b2bae362ebdded0721d5421cb845bae3c52517e96fc848b25529591667b0b71
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openfga@sha256:13f81a6458c47f28ad3928ca064cfcaad950ae916141844a377a44648db95dc2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openfga@sha256:2438b6d5375c431391a8661ad2d436ffbc97a196567de23d89a2d7931f0acc76
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openfga@sha256:62305a44f6c13de62e3b94ade9154a31cb3c08e19fe2e4abdb042aeb1e6566de
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openfga@sha256:7d3ced2ae126ec8b440528b690d259aed0981d8981e41f0aba1c0e07c827d84d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openfga@sha256:36e36cfbc6d7dc70914c5bef94cf2947df4d9371df09790824655e05a8249bbb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openfga@sha256:83fe0056e027aafb364ab2854390d449565122f54dcf6e6b0ec8295e040b1162
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openfga@sha256:34d6ad7de76c08fe298c365e4f21cb7d47392ac1cfceff8baf1b9b2f4ef6c5ad
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openfga@sha256:ae901178052beb31007bbbd7b503e83e4617c5320e2de2a5050f93b270c6e5be
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openfga@sha256:b8fb50d1931571e485d378a1f0fdfc85e9dc336431041b17eb7ca61ad8abc3d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openfga@sha256:16c46b4800273eaf3285d91e700b6f2c2d8334d124693c1e0fafa65c1e1abefd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openfga@sha256:0a112da175823f3a956d2e2af5d492d33819e4f78a279c8a7b74e83609a21bcf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openfga@sha256:4b6d1939182576da98fb5c05241685c983b811973f51c019fe1cf08bfa4f6552