Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.15-debian-fips-dev, 7.15-debian13-fips-dev, 7.15-fips-dev, 7.15.5-debian-fips-dev, 7.15.5-debian13-fips-dev, 7.15.5-fips-dev

Index digest:

sha256:c4b50206f145a540050a94052345335d87578e16ef1c4f3ac4d38545c696bc9b

Manifest digest:

sha256:7808c5b8dbf07573824a35a69930868f96b3b72444672f27ef42df2cdcfb82f1

Size

41.76 MB

Last pushed

16 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:3cd42dd911c16b2e4f6cb27f633da3c332f5a06a77973ab34c5eb8f4f5025c9b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:e4e709159025a75469f734481439ac6aafc4a61738f86c0764acaf23c2309996
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:9026aa19068176d1fa2a4714deab48a221e0cdc6c0648d1f6e78914feb41b66d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:f76e8d124237940c56fb93ed9c8bd697884f36ecf272f125082c54b2d9b75428
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:7de5942f5542a4d0bcae4c715eda41434ba57e2f34cf34bb045155597ee85b6a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:c03e21bfd21834b4545290447595295ffc3d6ec3f60330ebc563e0910b6fc70a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:3b613bd695431298774058ab17d90dc47feb2383f4cd706b5de5bb2af7061287
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:3e0fa1c399f01dab14140ae8927b57ddcf6edcfb93cd05dda13fff6333f9e8ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:8a044af00520035bda96af8113316190a6543ee2e0aebfb4402cca2a5d9cb84e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:8d51d56a9a4fad6698cce55fd1f544826c526bd916f8ee36459b7d5715fd284d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:5d250eb3fe94c14b3dac5100b941134035870011918892f75063aff1a60f730e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:9afe42281c27d3354641378f5086c9bb0ab1ece06757f6bc89dc15f0ea6b0bce
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:61edb83c901ac09304f71343e6e872cdbe795f032a8130e22b2a8612a2387b6b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:aba8d711bc68a3884e3cab64680467091ded912ab49e17100cb417009f011e0e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:4d1e0e058ca907958124097bf897ff52d460dc6e0af81badbbbab9cc86c7df84
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:c26f0f7857ff9b1a488af08e246a0c1036f509b31dfb62564cb1bb91d363ac2a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:a3a761c55ff70360dbe1731c6e316e1c8a4be191177ae5b9d90087dcfa6dbafd