Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.0-alpine-fips-dev, 1.27.0-alpine3.24-fips-dev

Index digest:

sha256:6cc19411a15286c3404c790dffd3a80d80068324d549c4bf5d8428d88c74bf2d

Manifest digest:

sha256:4addcfc9808b2d4c23dd5cca6bef6700afaff4010c5c878e47cfeeb920aae033

Size

39.23 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:c8d95e0a402f85bc2a30c6cc531cf8e2d88cdc1c879ae034a915b143f62ca905
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:992ddaa09768b3518b711087e4bd76a146ebc242ce5b96859b786f21b7b35e32
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb-operator@sha256:99e2d02e6541300331e92c0b1a02650a39b84bebfe65c81442398c4114aecd63
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:01c84ef980b423734ac59828de9cd4685fc83f794e33d84d3f5c9101e63d4225
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb-operator@sha256:726021c6fb0147d689bd6f287880fc9a8030ab19bb0bbc0bf383da2dfcbf791f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:62dc4dee9a235ad525f6bd6c833852661667aaeb3039ff699b234d0345e6aa57
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:7f3e6eda4919dd039513afa5f980b3af4411bf4317cdab21d64caf4e1c6f6b6c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:78f5a1aa69804b433cc35eeb3e2a9d6bb0acd16749e5f00c66e4944323209b24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:f08950da84391e6392a2dd47d26d4503512a42f315367cdf61b9df3d304c9369
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:33429fdf67d3d79e4f5178e174bb1a87e754409066a50003fd25e5e6ff00ff63
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:e7c9bf8d59f4418f63d2a66526cce5bcc47af83b2b68077480e0169ec19e1ebe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:f9e3dba2a9ae3a9ece52fcdffa37a8960085faf53b8ce534a868a01536e8616d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:2fd76b388e756208af92986ea299608c72781f54753ae86b492bf7adce35a4e2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:c577f042fc1a9e72dac82357e15e584a2b97e131f7fb8ff2b7d18e9f6dc47df7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:2b3bc25a962e32a4e7edc357d2f82992deba70eb854f4dc63730b70a2a47fe05
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:2aa6b8dac33fb4c8023977606606de15f8c2ddb970e5133faed599d60119f771
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:a686d60a506b895f05aad5a4da9c103897ad182dbde8c9d74c335c4c6e378fc2