dhi.io/authservice
1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.8-alpine-fips-dev, 1.1.8-alpine3.24-fips-dev
sha256:babba50521444e58a2d6814846de1169edb78592a27df62ebe87198081d4ac60
Manifest digest:sha256:dc6c566e438684602f6d82b70c7763c9231eaa67b449a8bce2d82560e17d06a9
Size
32.80 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:8edf718a41ca33e226af5c893b981cc1a8ecf6188fd7af5dc3d57aba6d9b8cd1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:42db54cf54715d80905f3064bbb01026023fba16198925e305ea219870689665 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:ff48f7de718904c47bd22060ad8a37936a2ffc9468aed59d12d3bcce97ab6874 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:f8df7a87a10723e7a9097d8f146fdda6282bf63e4afd8490a34b260166a4c1d0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:877855e80ee0c9c33a1227fa325958bb69cf5249571e714ea4796e41d76e8bd3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:53fe05b2fd95325be3ff8147d5780ece0c31ea835f7acaab159e24b3b6d87916 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:8bdbe3931e7fccf1170e2c4bb7501f8b379072ca95267a63bae83004faf4f7ed |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:5745489468ded13c6bcb9e41e3d8217bad9b07fa117e41223af6e749e43e38ea |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:87b5dbcd8aee536dfe67a9dafa0ce7a5eab964f9e2c5455bdf404020973be7ef |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:240d161044db7ccb28898cb010f90131313e3a5a243ccdc5559ec2f4d3cc4b4e |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:8330db9d739355df47a1a75bf191da218f7b43a9b8dc850f81bd30acfc8e5912 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:07c12dca7c71e382082f38126537c858c6eb1e876fd07cd0c5fede00bc138177 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:a3769fc32f5763c736f1cfd795d954bf6ff2b609da162dda9f30f0aa0213d8b0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:835f919db905c74153db39769465a9391db4b11d4be196fbca612455dd19fefb |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:59a8451a3400caf17171a2217441c8abf99c0d3fd363f9f59f3ffd926c6a9a3c |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:48dacd908931986741485fb38b39e210b06ab23e129c4959c501073862830069 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:9cf64b2aac786dd68a01b671cdcf55d41af7f8f22dea51f72b36d07cc4b0e53a |