Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.13-debian-dev, 1.13-debian13-dev, 1.13-dev, 1.13.6-debian-dev, 1.13.6-debian13-dev, 1.13.6-dev

Index digest:

sha256:b1aa1c3b5ab2efd0459f2746385eef2f96da73cdefcd7c73d3e1a5370be97011

Manifest digest:

sha256:b9e65d4e054e63ab842bb7a81bd814f7c5fb8afac4ece8bd82bd844a7a468075

Size

50.85 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:5fa98ed271efd905995d01233ec2c6b444054f999ea2cc6b38475e993942139c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:95a8ea0a5c664601f5c1b10cc4d5007f76522b171a34437662d2f4b04eaca0a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:a6d1c70577807ca82890081dcc63e777b73211c02b0a1ac2046befd3713c38f2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:53f86f9ce84cf98adbe9dc11b18095d7422c40bd250c189d97a8d8d861e5ee41
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:8b85bde9fa8a0ee2c920df4fa33d4e5b1b04477460ef286578793e568c8833e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:601ac01d44d1a5349ca6c31ac0d99f45a5c3ab3816326bf1dca211ea6bb5d3d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:c56d5c7e3ee2f65998716c3f81e18d83ace0f3ed7b373e0b447385f8ea93f160
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:868dfadcba0d62b752787268ced48f69e73ef427e6308ecfa7d88afc3077835e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:68e11c6ccf37c4cc9beb8fbb84ffea0689d06f8ed78d4d1880a4f3bf3a58afe1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:8863017e9f8986b930dbf12b2bdce45f3b4ce0daa286ff6cd57cf53ce688d09f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:21ac2098f6ea57f4a13ea4aedeb2c18e25a97667d09e84c0a7d194ca73b5c6c9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:068f8d422fc9e224b28572356a559770bceab6e927a97fe7334a7ca4eee2766a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:966315b22b05aa60a5f432d82c4d888258feb77827304f9f0843dd4bb21fe7e0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:4e5b414566a0672297466ca13984b7911393730ad9fea0a4accd060070d38f5e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:33d211b7fb2b0e45ec91108fce5d251907c39106df8721c14c38080d29d05284