Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.1-alpine-dev, 1.1-alpine3.24-dev, 1.1.8-alpine-dev, 1.1.8-alpine3.24-dev

Index digest:

sha256:e342f62be0cbd1af2ddef1f5703f1b2cf91ed0b1347576e79e948bd4af7d2464

Manifest digest:

sha256:5c303a32032f6998ff85fff3078cd5a8d7f1abfa9ea68a3937611610e576109a

Size

31.96 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:97d4357ae6277e3139d386ffcbadf78e4f0108417ba0998921439640566b3a62
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:a1b0dd8ce9858fe62ef488259a58d3f7fc2f334266642bb26ac154d199a7af33
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:90f950d280a2b414f7d8074918dbce7ad43704e7223e58a4297abd596dce706b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:078ec63c5d9d5347eb1e79c5cfd653af525a501d5009d5ab6bfb78027ca33c3c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:3be9e1c406d104c62b11b827bad73296e7d9202540a95401e231a39e71a49484
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:e6b16e68917d2cac9a7ab727a6333550b46296806f26a722403c6d5ea49c4068
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:fcb2728e51ceb4969349b50e459edef9534fda06f0a093766adea357fdfb3986
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:8b306d807f5795e9b6ae5ded45b99ee4359a9aa0c382acdf0866ca24176d69aa
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:4f85242fd936ad26c39965fcb144304742047eb164f2a12778786bd579a12393
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:37b977051cdef1cd4fa842c2289e8a679dab084f7d6d18b6ba3f7efbd05b3543
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:0c41bf96384aa9b3923989b06dda149e7cd6cf8c2c7b8c9769b7a6e81ccf28c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:81990d1df455ee3c821ad7a671ca494ac3a7604e0ebb35f60a20c641f7eb1ea4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:bdcda69c6885121c4492f46ab6f2582939d2289020f530fba5dcfb6640dab934
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:85ef82e349b7ae61d27780576518fc20f3d6485730bc0cd6504bbd9457783e43
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:b87f7cc771c750547055d95e253739100c6da30b027746414d6258c0433469fa