dhi.io/dex
2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13
sha256:696d741a0f673cf5acbc8000e6bf09f9b77a0eabffc3a42e59fa22b6995a7f33
Manifest digest:sha256:4b7ad6cee4805ea12abb9be57242a7ce99e63f2c3a44811b85b31c3aa162f37a
Size
41.14 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dex:22. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dex@sha256:10bceab85e9a7e761c7b79cca468cfb1e83cffe654a3bd133d627f537cbea4b8 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dex@sha256:d2379751dbefe03ea89a85205e912b107fcc4a69ac9ceceefa10dc83aed901ab |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dex@sha256:76d537bcd955754957650d0750dcbbde85a58aebbafa01c6e313b4c3ccad54ad |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dex@sha256:8ef85b947a6086b110c04edee55db19560406f0982de9129ab0667de66f17d8a |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dex@sha256:1ed530b34ceefd7bb0f09da500143d8fd0c42fefbfd5e8dcdcae576ac2150fc6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dex@sha256:a1d2b28a741fd7ac0f22286990efdb65b295c9319e1ffe20ad211354e4070132 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dex@sha256:f86e3a94b3d35040d067970c8ea62ffe4419e10214980eae1621cbf8a4c8d078 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dex@sha256:83286205c835b3695a3d813bd52ff9d88aa1eb1eebb5813b575d5abc8d3c3561 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dex@sha256:5fd2b544b2ee517d2be2559eff5847cfefc9d29da5b4708e9c955f31e6559ca1 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dex@sha256:b70551cadced93a0239e19762c972fb30943bb8b806c672d3c7066d398d0caf3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dex@sha256:13ff8a6aeb39e08eaad7892156441e8d334ea45b6367f1a55feb915d65c2a5b4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dex@sha256:ed88fe39ac847f6cfaaf7fa4007203a127328614c1cd0977312efc1b2cefbae3 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dex@sha256:a617ddb7bc426190499d65eace61a657fdcecd7e5218999e6e767c71dceb3e6d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dex@sha256:e513c1b8d74cd2d0c7577ff894e583cefc6e9a78807bfa9ea6e8e209fccf1f30 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dex@sha256:f335818f59951f75e58c7acfc064d4b5919b63dbd417f717e8bcee8b2b9fb02d |