Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.12-debian-fips, 0.12-debian13-fips, 0.12-fips, 0.12.1-debian-fips, 0.12.1-debian13-fips, 0.12.1-fips

Index digest:

sha256:11b8b0e6bf18543758af497af1f6988bb8aa54c33c55c852e588f0922d05f2b2

Manifest digest:

sha256:9e24e50dcb9c78c7b47dd1f8232c157995e7c4ffe82a3c797442d8b26955ab09

Size

14.47 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:820477a18073967f3615e8a285a15e546568e83c9dfeee61e2bcf342ab25b294
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:3a15ca21157a56df23b256a7a423d300177ae8cfb0f87a3ec60f29c975997d81
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spiffe-helper@sha256:15c3f179e249a4ceaf6e0673ecf73fbccc96e967ca8812fe9fe5f198c5bef3dd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:c99e1a48fd931ca4dbc68baff0a77f1393fe54d566c1f48a922283e51b000b6d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spiffe-helper@sha256:1eff2cbd95af11ea7f57c8a83341dc184ac15d21aad97d7371f36a8ce28eb7eb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:fd0f816231b149f561f889e46dcc6f1056669e2314fb8fe86742b5f093629d68
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-helper@sha256:ba17550e6322a184db30050374344db73a184bbde15ea70cb6d5879f363421e2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:6c1e40d620f585d6830e566b12cd01e0b00dd363ce8e9d0934435568165ae72a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:6bfd20aa0eff646a64824d71896cca47dab0d280078fe03beab446aedb41c224
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:f4051b9f1e1f36d542df495d0947616a6684a64ee1ac788ecb8e026d58a6e261
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:b066cd265d37bf6684087ed05f26193648ad2b1b8faf6ccdc06969951e134cea
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:e101d8dd1f0d79c143337aa0da716731a1b7afb4bdd37a946191eced1e8452d1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:bf0e1a91e03e8eb5ed9f5f927b885c4d84dc5dbf7c0f9de4f8f6a555f6fd0295
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:f8b01207bed6fcf1d375beaf106ec0d25b2aeeedefa32b700007e8f562090f9a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:c34aa4b8be753e50edaf46b97f56ba2e98ab7c911ac1b181cc9cee00e5435e8d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:0a9879a844c2a262abf512cb5068c60e5b65e45aac9d0cbd9758ccf8669279df
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:f6cfa24f86d063810f5316ec94574840c35274b114c6be34f05c0f92dcb6ae53