Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.0-alpine-dev, 1.27.0-alpine3.24-dev

Index digest:

sha256:439b07577c3c9be0062585775449fd1ccb0f9ed6e9f5558425744eb4539bf332

Manifest digest:

sha256:7542dc0169aaa0f50bc474a0c2cfbea4734467ed98d9e9ce659e0e68043d72ce

Size

38.42 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:441893c76bdd5ad8ee2c0f8e4c4f6d5cbc2cfab058f9396c6f0dcb13e09a131f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:a0315940004f36006ad315aa6701f58bf1ae8caab540be223ec11fcbc5b51f27
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:59c28ec2e12eeeec1ea97525520c1fb196f204cb61a147de9a5408497924f604
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:db34f33e0ac9f92f7399982986851779dc4fd6855d61ca6a3ff058076ff9c2df
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:9065fac72302c3a26073d72cfaf12b81b70c88c25abc21f442b91c83b9a8860a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:fd6b72cf0adede2989125c7c4312b7709ea483f308b7429dc454e87aed601c57
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:8a44644ceeebb1cce92ebfc00c15b6173cfbc4a896b99141ade3246464355797
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:613f8934db2d02b0cce00f31177e898bf41d76ae876995dec0a36e2ef70061d1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:9bc6d01726aa7b1a2fc0b96fbd336a2a3ac05f001003dd8830963b31f5209d5d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:10b6d20b834c8ab720dc8d4af6c9d2067857103336f14edf93ac4c5981a1b404
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:265fc3a611da142e89a1f81a29c51e9cdcd1c12824740e52691aa2cf9fed2676
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:3faab9e1a1110392f87a0911eddbd1ca2d3286a7fbe579af398a717fe7d8e616
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:2b90e891faaa81a1d249fabe07c831d24eb6e13535f2447ac9ad169a0a3a941d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:84ce0ec16c13ee2cd74c3f04531c6735a93738036dfe2e33b70204647c752871
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:1562448244b25f0ace2cf32911e99fe73093e759122640960c6cb0948cde5091