dhi.io/authservice
1-alpine-dev, 1-alpine3.24-dev, 1.1-alpine-dev, 1.1-alpine3.24-dev, 1.1.8-alpine-dev, 1.1.8-alpine3.24-dev
sha256:0ae3ca2aeb4c4fb708709ec9e9015a90558480c460c3bded1d88fa63144ef5e7
Manifest digest:sha256:fb9d7427c8aeb2f3549d6b4e58bd931c0121db088c04ba5cfd5ee842545d3898
Size
31.96 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:f23588fe199d165ed0a4961b79e01cd4efa5b39858441270717073f52d74b647 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:848d2191f5da6f6e69590bda759bf84f5c3acf1d67473e2759f49bbccce4c936 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:00115c11c6b956a0783bf48ca28d8c8ba44e52eec43e53ab270aea462239bbf9 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:183cd0b3549c2e1ad9106b40a2819b8a559fe6af58aa939890cbe7cb73b8dae5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:ff4cf857229bf2a353e8e4d2f8028af90f27a08630fd7f483c5495804a82d3eb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:e697a99904d81d75cae844c93aa790ea16ca58afaf75d1a7d4e2c2133d7d2f4b |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:3245769384fcb9ac1ed79cc49f83868749b458434357db0b3ce3fbe86af55657 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:99a4d2efe3f4d2489ca807a2efb1716c873a520035d11d4a34963dd2f4447549 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:2e8c2f68f99f741f2a5bf570000209eba808de31ef1d00dad7174eaf52720a4d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:0c8a7614cadc3ba27c85797de3cedc20d7768153402bcca4aafc8ff301ff93a1 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:f4095bc78bc188980411810216c1991ab567a8faa9222cb7ed070bed5d883935 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:ad78f08333aed904c2d816e6b5b5bdd2957fb55c454b015a0f62e9f97be98bd2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:9e55213dbb135cc5a5d5410a5594393f916e7345cad6503ca942d55f53d3fdab |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:6c0fd1da85b08e36cbbc4004b4424496d1fbf7d07cad4fe20f81c9f5f85a35cc |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:5e0cdb798d1133dd250663ece09f130edabb3b683148d4c019aa9e71e327983c |