Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.13-debian-fips-dev, 1.13-debian13-fips-dev, 1.13-fips-dev, 1.13.6-debian-fips-dev, 1.13.6-debian13-fips-dev, 1.13.6-fips-dev

Index digest:

sha256:de83f30764d5a8b849d1a08964a74390263b0f63e6a7fd6c62bc98db8c275cbb

Manifest digest:

sha256:64385218a322760abd61a8bcc5cb6d9641c11cdc7ba8f455a4a3d0449680eaf1

Size

51.59 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:66e153fd64098c9bf219388c51b455bb8bbc4f422cc8a51bbfbc96d27d704f27
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:595fac5c92cab1573ce8774317d9a4e5cd1753732f2a1f6b5709b05850f24aac
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:b0acf94a88442458de5ae5a04800d316a98df4919d2383bb05ff831a879037ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:c717371fa30f4e810905e4b5362e9c1ec9c858f7c7f2ccdbe4555632e2d2cb32
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:7fa4db4e10c647e784fc5fbc256b8181838a60b64093fed18ab32229ca5b731f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:cdfcf140a201f7332f92b56fe9b702e28d569dae0a5b1e57f228d32316efdc14
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:dc97f10aeec656d5a0c2390d201ca077437a2f4ab4e5acae69f87c4d639cdcb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:56dd2d99830640917faf83e0d2402119beaa09652cbffb5edd19ee399998b8c4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:5fbe646dfd774131af20965fcf4c41d9196c808d78a5c8ba0c8eb4b308354462
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:c578e78ccc951ac63e1867ce106f5e4056d1a395353e015e33124c5a5539632c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:2754e9131c32aa254a2128a72a7a1d2adc5386f19efd07363e012c818a8b1deb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:7c393ff9105e9440c8dc744d28ac7abf86cfaf04598cce695fc004757d92450c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:cfce502a43a9fa5d52de44cefe0cc85eaaf6ea8da512697a38c28d5d97b5b983
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:a3483f3c8753fd4c69dcb280b2801f784ee7074abb8c62cac0e8e9a70c81fda3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:2e2573992305c3e2395944426f3184de8df9fe339ec764e752e551e23dadb8d1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:d4311bdb4ab4daeccbc0052d7471798aecb783cb0866f632560e90bded25e4bb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:918b7ce635cfcaedc3133cb20b53906a955369cb05807d536d4d5cfbeb60bdb8