Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.0-alpine-fips-dev, 1.27.0-alpine3.24-fips-dev

Index digest:

sha256:35d63ba939329813b05d843f893cf05091b53c17fe2e43d9d484cff28474ffb3

Manifest digest:

sha256:277b96e6e97f5ba443a81a95af3e686ea6739287c2795faa1b7292e20930ef74

Size

39.26 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:cba10ea1dc64204bdb54d926f72ba16dbe6eec714946788b6711a4598078fbb3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:8ad62725d679b8d919f657a4bb98ad6c79f69ce5d1a82578a8dffff762973744
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb-operator@sha256:ea6e901a80af5800274f38ccf1c192c0e641a37e699227721367010fe21698bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:6533d6b32a867166677e0408601471ca0d0ae13105a65e7886919cdcec2bd5d4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb-operator@sha256:3faa16b370afda1e854ed1fe9b2e753a68f70d72b9d80a58e4cf8dbaf2c5704b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:8714bb6b85489399bd789c78996fcae155b396dd50c04d71c8b1af685b0c3cc9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:539b2efff9d50f06a0d588461b5b9dd885e559d0ed17b7d7680b816879ac96aa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:461e6024e2df0860a985b77810113681251b57fbe0be159ccb5d5d870b716716
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:fbe7e61c2f3b2ad6221e10a9728118d1b25da652a81ea3b3db4a2d0e34a53d9d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:4a0f20d30852b9dc2f9b28c50479bca85f88287f812b95554c0720462ff60012
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:d5204ade99d7aa2197e4690b43ed42ddde52a6dc9612e5a9005290d1978210b9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:a06c4f7b04eed52a5a6c80c8bde18a8c20cad8189472fc3abb7ed7aad08646a9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:24ea1bb073f31f2bf6c493fe0194611eede60f6c4dc9d16a9f3247746758e0ac
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:9b12a82a97dd6d2f84546ac50329c0afb24cfce6f0c4edebc773d9479535c058
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:ea7e89fed31b0778d0b7b1638c17f47bc471947253c93b4b6f7dce061f759c5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:8b9687a58305c3f6932f48b05f371d8a83aea1a9db81599d4f3b077ee89d258b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:fd5256b31c0183f09c97df80c665c50f02e581f08bad5128b7624e3062174042