Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.14-debian-fips, 1.14-debian13-fips, 1.14-fips, 1.14.7-debian-fips, 1.14.7-debian13-fips, 1.14.7-fips

Index digest:

sha256:d736129a595531bc5740ef08ce111691e2db008f772f6ab3e4ea4ee3a13ce9a4

Manifest digest:

sha256:eeadf065a9a8a7c13b2ece84a341ce10001d52f7326bc2952c60f9b6dba33a3d

Size

22.78 MB

Last pushed

15 hours ago

Vulnerabilities

0
1
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:044d879020b8565e9f48435c4553d194788e1908036a036a589cd62539e81852
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:b380ab4cce9268ef3980091b89ac26c777a7c7910167779c371c5e93175445fa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:a042f447feb048a05ce91d09657bd7a9dd8fe448df2783e0753fdbd8342b75f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:429578c7347dc4ad02f080d40686b863120fc2c771718307f5bfac6df809b199
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:d08e7a83bc915e50eb029f0029819de8f082891cdc02c6ef4c0b7233e1acec52
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:78e124461ba0b02d4bbee8c6623afe180ff78eb7eb68a232d3a9666a239ec099
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:cc1270ef3724bf3d8db393051eab9f948cb3043e036d5e988b878345cf66b6a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:acccdbe7956705e06e018981ef93c60279fc062a90c4160c126f20079f7f7bb9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:50e0d7f60465929da533b65429a31c07f6cd804416b1076336c00b577a5d1a47
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:9cedc64c1112b09ff7b05d64ff7687db97c86ee20c46141960f845095fc1020c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:fae8e7b1542365bf8b3a9f0e25cb9aa510908ac279ca47047dd9a312b30b09f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:69a89827da6e14ba662e52f9fbd538ef345330efa7eb1a41f31589ad8effa6fa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:f3dcf37b7cbed2a9ab128a31d42e455005b065b108038da7ae729185e3876a9c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:1be7ee0c1654637c3bb3b98e8021699d7da208ba6f100662fbf38e97f76c51a0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:e37f675a76a122db90540e23ae0c2a137e26f13d52a242a68367ddd9dc025ea0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:eae16215277605afb2a5e3ffc817877a0ca6cfeea445e0cc7976e7cd1cde09b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:64cf73917e47121ba481c8cc04c96e6e78ccef592480adfd5fc6e2e8308dba12