Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:7fca83e74da4fbc30aa57d2f113a1048b7574119688977cf2f84993e27c8173d

Manifest digest:

sha256:bc4db803b107f8116b07fc03120f343c10293f5ebfdb55fd3f4db05ab591d10a

Size

52.09 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:a8cfa68d7f46fd40bb3affc0968676501acddb52cf0887cbb913f0fb46fc95b9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:f068fe3ba29b76bba96a87aceaa0a167aeb3d7bc27147397c0a1747dd22c9811
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:743a1611b9e230b94fe1181301b0e29cec52609ae9ef10fda151e00145ec4820
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:ef0a5144800f781cd08ec4c23b034273b03068a878d5b5aece84223fb67e18d1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:bc4c9aea48c8534a7ff5061c00e2672a611d80f9369a76ff0fd4850676fbed57
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:8ae5c98e7456900608ff0ae7ed2e17fbca226706888718d3bd320d998862350f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:bc8c790035edaf68d6c7e72b381b03da11485cc0f95919bd89f43406632c938b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:10c05ed8bd8afbaf3d7e366413647e33cc1786eca1070b7330aacce482bc9437
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:af9b287f2d4b86b57cd96fc08509b33e3186e7a8785986ef4574537c18dc1987
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:e76006bf71a08312b00b432dd646601e87a7e2082c3a122da31ac718f7731229
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:58b4fad19c3cabd72ac3708d6d16f0dac2c507420e9a62e6d55bc555dccc1114
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:0eab72dea08788bc3b8d6809c99b5a595ba71d9f5bdbbfe7e05cca9ca4f83b37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:28ca8199f623ea076f0963eccca0961667c68a23d1c8a4fcb5d0731796b320b2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:26eb9f7d1f4ea31bdf1283ddfe9f0770aee4fee629aeb71b87f253187a12475e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:b77b2605819127c767ba95c9d63b96b2e852744134433e66d752decfc5de96da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:5a5754d1c12402502277fb901adce04c791835f39b4833ddc683b0cef924e066
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:1e5a8acbc7e61558105996dab520b793da2e4ff0255011cf6896fb0f5ce6663b