Sign inSign up
Ory Oathkeeper

dhi.io/oathkeeper

Ory Oathkeeper 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

26-alpine-fips-dev, 26-alpine3.24-fips-dev, 26.2-alpine-fips-dev, 26.2-alpine3.24-fips-dev, 26.2.0-alpine-fips-dev, 26.2.0-alpine3.24-fips-dev

Index digest:

sha256:9dd3366f9f7785731b227a9b521c3cb50471564ab29e60c6c0bf990b8bf14def

Manifest digest:

sha256:9b4927287081c90a3c5a2de7f1355e4067fd47dc5a542e61ed920855f41bc752

Size

36.35 MB

Last pushed

19 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oathkeeper:26-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oathkeeper:26-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oathkeeper@sha256:80282b3ef1c3f81ccdadd1db90d7298410dd951543275dda153fdcddabeb6096
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oathkeeper@sha256:eed14c5cb47bdad7b1396938c0fbf4009edc9f86cd78451d52264fd122fa7a47
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oathkeeper@sha256:ed751bc52adfe36e65cb149bf3aaa2bd6842255205368effc6ea182de9949605
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oathkeeper@sha256:5f1df9ea51234cac452354b0a9b0a69e2c381c5edf360a3e772189ad2b406813
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oathkeeper@sha256:4e63d1e18b1335fab8f0b94660001454524f33ca4f80b4ec155fce730b99aa1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oathkeeper@sha256:4d785fc9628451bd3ae1fc0215d1a54555e8add5d3cde4c8432402bb637596e6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oathkeeper@sha256:5b56e205110f50f8d5f59a6669707d12646fbc3e8a0aebe124bdd9a56bf2ebd4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oathkeeper@sha256:82a05ef7b61909a9c4c0777f7250494224b4e9b7795dbb46aadb768df5c20b47
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oathkeeper@sha256:f90ccc6a99d29c092d6715e02bcf184f9f8d9ea19600e931e26def564de9f5d0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oathkeeper@sha256:f5160f429920fa45f320b69b3b5f3d2e0279f92b127024ccc289bbebcb9f8c61
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oathkeeper@sha256:d1a3f570183cd88847fd286eb19695ad9140b2abbc3ea5d15a8647af98d56d74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oathkeeper@sha256:9bc0df4b85a7729d42f5daf71fd696d100bac93862e9db3dee05ad2499e41b12
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oathkeeper@sha256:a9becfeb045087a66fe1d1ac6dff89e110fd64e8931776352ac69802f0521cf8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oathkeeper@sha256:22f5f5936302e96162758826e080f440c55c08e5a183f55ed8826098eddc2ee4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oathkeeper@sha256:c2b1442c37a0020982000e52574c01d0fbf4e4fdc563ce2f73e8bdb26d24127c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oathkeeper@sha256:234aa07ec94f17b0433dd16ae8e17e1b8d68eb13403f57e58a96312e3607c664
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oathkeeper@sha256:4df6a35b18a1827cddacf3b90b3466cfa228ce4fd1b01111ce97a0c18d840f24