Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.13-debian-fips-dev, 1.13-debian13-fips-dev, 1.13-fips-dev, 1.13.6-debian-fips-dev, 1.13.6-debian13-fips-dev, 1.13.6-fips-dev

Index digest:

sha256:809f57a6ec0b12b2793c4a5731dbf3565ac8edc3b3c814967ee99d389865a680

Manifest digest:

sha256:a5c9c1e20305e8dcbdd6e451d20beff9989bcbb7bdfd36ac22b29132f93e554a

Size

51.76 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:5841838d8fc35d706a8eeae50ccb21ad56843a2ecd965232541aeafb0ca9f9d2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:e83462c2620f34c67623548d16862a8ba0e40639ee11bc2fa85bcc81718a9e6b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:cabe4aaa6adcadf5b5fdc1fe662e7c7310bd7a00212d257fb77431a556738bd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:2f6b32fe768e0d387b5eafefe8a7ba3c086b12e356f4ae445bd091edb5934c54
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:85c272ffe4e4fa356207c2c4ea4eb0cd2df7fb86c2d0ebf25fb262ef432def53
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:0f42cb7805da4e120630fa324c3ff20d729dce4817b82499e5c3a73fcdba8aec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:f1e5730c9cbaebb2384061c779defdc027ccb539ce259b93165f5de3be429261
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:a4c5f3cbea6d5d9f3ba75e7bb25c091ff9c402a0b34929d8baa5343b1a4f1500
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:7ebcec60d4109e54c739da227e541e58791a41b70cb8a9e0b2ff3412e2b01e4d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:827622334121585eddfb5e5befb9fc8c9ac9111a5458d6f0239ad5f9df528b66
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:e984b29cc35ca5ea678c35c8d4a5e673632dfabe1aa2e36350e961ca9c0fee5a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:66ed64c79aebc4be1ea408a47b9f93402afe8fa22f15ef63605c8f988dbe8aa6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:89f8577b6771602807d8ec27fb440536123125810ebae32980e40928684985a5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:6c78e09e712b7476e01cb133f368fb67fe7a5b1d8aa40c0500e5821e626c3fe0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:d8f4236e4d0f862fb707f023ba5b3eb46259d50698c446a956255c98f82bc10f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:f706f726e63b5d428b6c0155af2467ef98e3f8f3eee13a6b17838b6e88946847
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:6ea5a35a8d94d9627693e0abcf70363d09b90d943af18b137eb9f80ecc1f0304