Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.13.x

CIS
linux/amd64
debian 13
Tags:

1.13, 1.13-debian, 1.13-debian13, 1.13.6, 1.13.6-debian, 1.13.6-debian13

Index digest:

sha256:9948ed407e1a999fa28355bd002fcad167e98611899df8080619a982d00d4733

Manifest digest:

sha256:790683e0504e575e0a501c79007339ebcb1d12a2284c486f16e865f8e3bfc572

Size

38.55 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:27ca8c4ef5adeb88aad457afc3b919a8d1adab6d54ba4d77bdc41bb75b1060d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:df5466ef7c0921d613ffc1d638c83afcbda47e766586bbb8a3e1674a87f23c74
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:96d1ca8330a2a3c4eb0c838b2f53dbfa1d343433870c8addf4ff05a7a9ede2c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:7654181e631b0d578872d288b68948192ab56f3ef1fca4ade039d8ba9b153c93
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:5979db38789f73b9ad246fe83fc8b5bec192bdc1889f1ffbd133253e1a310f2e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:767fe4bb9d74813a1e1e89350e5c9cd1a90b8774d668715ecc40cf327ffc5d02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:acdbb0695f19209b2d66484ba0191e28eb87d78a204455469c1b7109298b5fe5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:998a8460969291322293a6b333530dbae162a533866de65e461724b301fadad2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:fe5dc2ab7a50ace02fcfff98d21a70b4299c377f65a40a4c36b206980daae7fa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:fa92a48c84575ae3e2082079125ff5492c58a29b09a78ac9fc8f7f3f286cecf5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:71ef9292c0a4bcef8311a17c0c9d56e8d544862a5001645c28f15c3f06336962
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:a49649f392bc1f01afa24bad3fceede61ef56454e34c805cc67b067b97f5240d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:f44f27f82ff53d968b0202d4b0bb9ef486349de5f25419208ebfd955404920b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:70d3650db146e20eed3c6f8eb030dd1c57889ac6eef3b9fe2ad8985d25e348ec
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:7657deb40b1e4266207a39ccf310abe802c6c38735f77e9034177b7f80e433a4