Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.56-alpine-fips-dev, 1.56-alpine3.24-fips-dev, 1.56.2-alpine-fips-dev, 1.56.2-alpine3.24-fips-dev

Index digest:

sha256:a61dbd76d0bf698b65ff4177afa437ca65b195b757ed11b11b7927a8241bbb86

Manifest digest:

sha256:8bb9973f00ee216a5f1a5b83c85c44e89bcb514496dba62587f433a0bada860e

Size

56.63 MB

Last pushed

1 hour ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:5a830a04e7ada5d1ab4ace33e8058f7c3416ff827df3114517b03ddaa42ebb98
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:9484fe93ada3aa92d742c67e6c129b17d35e9bd32cf3f3e568a11318877ebf33
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb@sha256:a488c0de090fbb941de4a7186c5283ed8c6807b993627cabb4fec25d692f6861
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:6fbb82d28a9939f770e61156a22ec302f90f3b3a3de8b4219b37250bd9c90cc8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb@sha256:c06e86c674d6e42829e3b07044a0493b09eb5383c19c9e4b7ab33e184901ae05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:83c86862b947aaace9ada4d4a17adb6e2434e94803c23ef3b696ad12790db820
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:913140a5778101c5a175112eabee30fc39552748873b6d3dacd8802fed9d03f6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:ff022f707fbaf1ea63ae6f027c87e30e4d747de0e7ea560103cf7e047ef1eb1f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:af93c781b4991b49c48af6be693f17c6a1ac36b2c02d6eda1c75e69a65c6305a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:4d7b05aefa9618e20f72b9f2c799adb722391761b17ed469067cac521ccaadb8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:ad0b16275f08d41d67a213fb29d3781e587150fe802361a68aab41c9d5b57a35
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:43446f421d71fea9ee42f75b3b8ab2d76962cba1f499c8ee1a8f4ca9adf74b5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:50d1c3bba2c35c1e2d8a766b70ace8d637b0ab75fd37a8a03f40c40cd386e5ce
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:20cea332180f3f8116d503e64899ac52d15d5ddd271b3f6749dc41cd73443e51
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:a1f0f69ea6c24295e496bd1134ebadcdc7e6c42aa157607770856a0a463ba1b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:55d8e4ac4a2362da6f7bf6f5853432fe86d219f2504ea2803ba95d2b5c40f4b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:279b45637268da66ee2af9ed112d4e03798b870f081e9502630605a557076663