dhi.io/spicedb
1-alpine, 1-alpine3.24, 1.56-alpine, 1.56-alpine3.24, 1.56.2-alpine, 1.56.2-alpine3.24
sha256:5c597a0b12b9f68e831517028aed0f19b0a62cc342de3e6590e6c8cf8c35f18f
Manifest digest:sha256:cf3601d1d73f48e6e9a25bb141b8fce8e1bfbd76ef837f02458df27469648279
Size
26.63 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb:1-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb@sha256:442d43f85d0b9f44700cfe64047f90f6eaf36953d5abf6acfdf610801db54122 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb@sha256:74c6e0910e7e5d9b0fe505df85a58a2fc7b5cdd9c2395879172e29924a5a8ed7 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb@sha256:5eda96cde0cc328bbe3ff3400d3fa56e1aec8398f0d0fbc82e380337f080aec5 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb@sha256:ff1ef287252b9ec57f67f6e10c32e058a8edf453f74c3db652c8320bd2aee34f |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb@sha256:0171b4dd654ff93fd87ef9eb9de512d201accb873daf0d1fac44e9b66eee0874 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb@sha256:f852024841ad2885f555ba43b80283f601c1849b2598940ca468e18c940673e9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb@sha256:c308852b7bfd038c5b71b052f483f5053a70eee226955cf82931eb5f35a33a99 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb@sha256:14aa90edbabbebe458ed5fe686d025929338fcf790e5dd51dfd6e2c643348cc1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb@sha256:bb8beca39a52cb016c22026100daf37927a0d980d43ff9df44b082b73a8c5df0 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb@sha256:dcaf282f3e528562758b3593b0adaa8588d48a03eb75b965e9b970adf87fd5fd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb@sha256:c2d5a45d3a1da0b1d6d5091edbea884690ff638e2eac5a4a3a9bdaddef7ffdc7 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb@sha256:4c57d18d89d5fdfc5a6d0cc9820a053f12d83f1cf2e081d69f9846a2ec55e07a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb@sha256:512c171f139c51c18ee86d1dd61d34d286186b2cfeee3cb9aa39b1100a78aa64 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spicedb@sha256:7d65f36f0942cf5d8ff9ee5d033d972a1a5fe7cbe185ae6dc218eaf01907439d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb@sha256:cdb56acd2323f644f736c225eaa1bde1f9f0e00dade8ba9376c4437ef51d71e5 |