Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:01bd1b3e42563c88d47bc25b27d7b1215b224213eb607244b8a7b84530593e2a

Manifest digest:

sha256:7b6378ff9df4b63e1d0de2f666b55e19436a2c1bca0f51cc1f9c24ebdf113e67

Size

52.10 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:825c9639a340b1bb1f3682bbd4b812bf7b8e3d9380e44e4e1cfd22efd90bcdd6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:74395e5e8aadb7770488ee4551470d7dbea10a750ec3395a9957360aca796ce6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:b6d4038ee284eaa052647ff51e923aaca994668532075597cd7912cf2078f420
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:9c66166d3c7677c14c389d825a0b0c9f29cf3b57cb43af94eacccae6e0b9bb25
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:b8a6f36fb1831d215e36a1e15f69d050ae4cae60c230a008d88dfb8ace0ad826
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:b16fec942ea09b61b66ca3ec711d597ad2e5fefcee9622c011009386e6ea803a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:51a580aa5ee25ddc26202fe9411a9782b5ce62ddeaa58290c494d4bab0b3b48a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:ee42ba1f36d638703c346063baf66281d1feba834a66fdeebfdd21faee82f24c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:8048be502e045881f278cf24caf1155eeeaf942858d4df70b07977a588ebe0e1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:13bfa5aedb23dfe945602aab25fa483fbec53b16e5ed2141c2193cabd2c19f44
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:46c4a8bb317f8ae8ecebd86b9db1a551a03972b6f5ce5bf2e3bebfcdca91a9ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:f63eec988a0458659bf4792725bedf68b291455dddee187e76b655710207e26c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:d3ffe71b41152e6aec36357fd86b139bd55438f3f0e97869b998166d7fa5e863
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:7cff803ab91b9ab0658418770c9d830a03b7d0a17026d0cddeebf4f6df417e9d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:4779d9c6618a55e6683de9c97d7bf0d7573a1c721e84586cc15ea601608b7d85
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:0be74386549bcf2fba2acd503e6121c3031f2244a70971afa861dbc23a95ea4a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:97e8ba74e55e9561acc2d2d6886338ab72d37dfd4af88d4adec2b051717e4585