Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:f0b1f1f7a1fd51610216fbd8986a1c8f953c2a52bf141e7e1ec5dddaf9d5c591

Manifest digest:

sha256:d77aaabc6ff152f06a7e12f12b219fb582f0669218c0403d2d22b6faf8ebdd79

Size

52.09 MB

Last pushed

10 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:d78951cb6378a8d6b8a1cbcbbb40155dc02bbba4b931a0f6fe287a0fd9c29d0e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:b9d7ae61888069c5d0956adfab21d9362b81de960c5b2487a029e67fa761e89d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:a1a129279ad4b10089744f356a4e02fa5423b17f409106295edb084db4ad51a9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:e6825dc38ff2e8b28923cfc3334de83119a9fedcc4f58eccb85a991aa07d3759
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:356cac4c1b335621e8da43a1d395463ac81eca014e4f0232a62a3edecf31566e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:fc6a2556b7aa545268dcf2a3ae80242fba2579fdc69f089d2f998866ecbb4b33
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:0226468783a2391f71dda8f0816ecca18ece7afa1b8f787079aa78c2d0da547a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:aaa18bc7cee6e26a871d7cf6f146bddd0d8819e1bbd3d7734ccce4c3a0bdf5b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:bb5d6633670baea36e27df2b3ea6ab60113a6d64ddcb98dfcacfc6fb516b7d07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:0b32c764415d0ce7315b20d317dcfdd90b88b025351421bbd6e17e660bc19e09
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:5483abbfe4e8eb3c30328129cd109b1b3a115c9a0cd21c77972c439c0d8c3c2c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:440acf051d8f5d1189426fe1231f77f46a725e66a0ad948ec8f21512ec645ceb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:61ac7241cc0755214780447127366cb2b6896073ac909aca9545bd12342cd615
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:b58d29ad4300abf8c88fec8fc9f61ab0c7f38e0423d29322aa257f0596dcaa58
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:aaa4069b998eb5a99fb535f0d3aa84f18efbcbe26d41d2a6c25eabaa54fc1033
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:45add3aef0dca8a9b8abdff8e39f27011ea8d9f06548449f154dc4c8a1353632
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:15e0d6ea553e31ffd87846e29cd4097a5278acad09a4542c6dd0d1a044c217ba