Sign inSign up
Dex

dhi.io/dex

Dex 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13

Index digest:

sha256:b332e8955709e29c9fd4723f54f1384768968eecc163baba523940c6e125ecd2

Manifest digest:

sha256:4da9976749251909f8df1c0f17549f7e71b26ebc711fe4b661953e98bf4c4e8d

Size

41.28 MB

Last pushed

8 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:320c06579be5a9c3c2cf29a8d2970c6fe6536f251dfa7f31addd68be536ee9f9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:ab88b07d1b865b597636e10f5d73f95c702f2f09ec69786abfa11f62ed7f6eaf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:ec0cfbe921823885d93fd2d026aebde2f0cda8d716446edcd49ebdfeab8586d6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:c1e6b1d9575b3dedc842831cc93ea5f84a38998f10a6f15dc544064d97981968
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:68db4b4ae115c8a872ba021342c51a00f48283696ce57beb7ad55666fe0cc3e0
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:570d62b2fb47b045c8166baa388e29e56b722b24eebe042d04fab0b9e840f9d6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:9ff903c3991b709ef6c4b1ea4b79453d8c65fce94bffeb1982ea62000ed95fbe
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:84b22ac10a8874ddfce103889926e6bde989e8fb46c977d1419482fe8e41ee15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:9d638913e1c5729da9c9c48fbc687bcbc50aecaabc223eac2268122022c7507e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:0161311b4a813f9f9ea935cd54c330053aab8879cfbc2cac69149c6bb8b8a323
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:7837f798294078f5242b4fb03ac084ab412569504ed3c4235062347c37b94b04
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:d2e9fed3c781a5f73a48b8911ae47670a1c4381b9d7e2288775fee7c0aac108e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:0d5d9ef11f7fcdd36a946b6881e6dde0653db7c5904591f20fe4e9e7b5ff8e69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:8dad6b5ed5ff6d15e3ff12fe249e167528b87ca612e2e792c86fdd69e7ee9c5f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:88428b69768cac9992888c7ab2efa069e8ae5af2d2931fa73fafb53f9df7ad6b