Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:b9555f55e44d1e42e2ff6b20b47afbdbe29a5e3bee0d6e5390b8ee85f31fd08c

Manifest digest:

sha256:d93174d8ec17ab1311291273356f1ce6ab95db13f4dbfeb12bcbd812c368369e

Size

52.09 MB

Last pushed

15 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:b940c8fcf549f8ed23e67e5da4492780227d69b2e6abc5d9f7e9056decbc9929
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:8efc5398bbae13f913d97e07da26367869f6ead3877a5f97e1d87d98115a9896
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:9dddefeb49484d01251bb39d2d08fafaa437e6fd7a51e1abe4f283535e66fd58
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:f582236f1acf649442a862edefaae778c3771bedb7d0758f16b6355f608370ae
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:0cb3c0a8194eb044cb61c0d7998b7735019a817f27011a45992682f203f8fe20
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:069a95384442bcad6294b6b1dcde3f17246a9708726263717eb2c9c1a4f3f4d1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:b921af59a17b76dbac9aeac1b99585048ec52f66a33536a32f77675e007af304
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:d544f6fa95e2cf23c3055b0d4c173bc393bb18eefddb34c943b391c742aa5546
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:55e1b177ec6f87f0f4455c7af7e2e92b1081d1bb44aee5808b2f9a541e51474b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:0d6c8386110babe8aeccaa5c46f99dabea42f3cc238933070b949a40654e90d9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:efd49e767e160cc66fb5a4b5f73b12cef41e59f1800829b339f3232dc5d0d794
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:42e7c684c9a04d98df4cd196f5caac4569c8f0d40749eacf3cde1e29ef4da014
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:8b3b910b8a48e8c258ddf3c609654e42acd61b7b8eea58a0f4f81bbcdba97d8b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:1165f0882294f59b696b3d9d8712e4fadf054c02c6cdf6a457e8aef340279b0b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:671444fcab5684aa7a8ef5fd423c6e1cb3708e1670340c5984aede30fc837278
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:5b0594869c25848f4c4cb57117a1dd73a85d705f2235810e007b24f2d6778faa
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:e427044c0142a3d286b23240f283406705a12258a6a23c715770e22fc997c400