Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.1-debian-fips-dev, 1.1-debian13-fips-dev, 1.1-fips-dev, 1.1.8-debian-fips-dev, 1.1.8-debian13-fips-dev, 1.1.8-fips-dev

Index digest:

sha256:2811d67e870194c374ac31a2918f2185f6f4cebfe7be8e71341c1632caa49df1

Manifest digest:

sha256:f3c29761f3c1285a36aca0fbf9d0971ad3abc46ff51b11b08b64b8d25ab2f2ff

Size

52.09 MB

Last pushed

23 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:5a65f4326e33f1466b965979d0e04310e373157b271ca7f5b73693edb45d2cf5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:8dc9eca322a75248176b7a3bea17906989f6861c985482768895c2a4454d4e9f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:9ee45f2ff8e503ee45a10fa6a899d6ba9d1641148f58747c8b8496406b7eae3f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:f4d192975bc1adfcd38e07d120f4629ca9d4004f63b1cd5ffd2145921be1db3b
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:5da0305f1dd184adf077146c284f522968f10fb4f161341a3568af14c5300473
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:fc3fcbed9be800dc0aca54530305af19b2421e9b183cd45a6fc8592b75bae8c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:fd8e3a8ec57c3febfb994e29a567ebbe2928c874dfd2f2a16babe0fb83540ad5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:073356a2b6772195c479093d1c6cd83135e334188fea99e9e36a7e7dc6ed0ec8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:c8e85af74133135de195c846c94a5bf2da17cc49ca6e03b5d9a56519eba5d8e9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:2e20ed9ff0de86fd61410332a9c30126bbd44fdc39ba90820117cfa500e19f73
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:548ffaa8063c688220e58af39e1d8ff897fbe111575bce9130887a26991b75f4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:fddd20fe18152696d83624c630e812bdd5a0d109d51e356fe325d2a574f3c62e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:5d72ede05da65ea7adb5790ca24f328794ab52242d6772d619d170604869264b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:7a40889767e1f858e6e39f814a64b3970d631ded2f12cbdc8ddfc704ffea87f4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:2364edadfe8c700fb4e47c6b1db22be70363c6ff8a7894649e4518fc1ba1f966
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:f77608ffb5007670ce67b9e092da4634e305bc9742a72ecf3876fe791299e243
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:749dac3d0373bf6f6dfa95311402eefdb7c225b6e1ff046b45e30f703aff2a76