Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.15-debian-fips-dev, 7.15-debian13-fips-dev, 7.15-fips-dev, 7.15.5-debian-fips-dev, 7.15.5-debian13-fips-dev, 7.15.5-fips-dev

Index digest:

sha256:caaff6a5336f23d829de051207a9a5dac01fe6d9f4af39e2093147645ff81e75

Manifest digest:

sha256:b042237813459de4a0ddcb44184aa0f1f93b948c80258e038a134f415eda0daf

Size

41.76 MB

Last pushed

7 hours ago

Vulnerabilities

2
8
0
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:5b4a90aeb74c3b4c5685b7d6860b527411b0302d8e50976bac044198b84c5ed7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:94eb49806cb6e5d947b2f54a7cba087f0688e528d9d1b5517b80ae50fe8c5436
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:036a24a5b5c2d3fd978091f9a272eda04b03594503388e8c633dbbb3a26573cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:31eb263e722f84f49b0dae3f9362257d4856b2fc3d52aa2a839a611a8bce0d3f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:e0cf4eb0ee5cb88b5abf6c1a88fa83366046344e7a534f683c25277c9ed19ca9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:fbf9d4ab32a97c08a9887da446a9258e97cccc461456a47356f802ed470a678b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:71f9dd08fd14107fac98729bb9cc0b6d4336c7936bbc08440322fb488829e469
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:d0031e382a71726b4e76911b4878512deaf39f81437ead0fa8b3f7ee1f9737a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:57ea57a1d856db03599dc9e4b4c87d4c1f9ef5a321f58ee81638b94dfcf3d013
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:86b5c4d069ccda95112f38551152264552b7f2c441608ec07cd1499451b3f1a2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:4a5c15e54f403156af226732a5744bb768b3109ea0cc6416580b5a87930cc19f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:5dea39edbc0707792e4f8803028b994251d482ff113c9dc50a9b1b1ab3a60e37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:773efec6ef1995fd2b7891699d60f18609a9f0eecb37b2dfcaad9525b53f2748
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:1dd4adcefcafd45d62ff8ed5194a2eb357dad03b7e16e70ab5e7a3be52b46c2d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:a3e203111dc765a559fc26b8c74198467efbd589a6850c30656dafa49bc772e7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:7a4bfb63895ee2ad75bc10d42bec4bbc0250c519a48d4d3c8a52bc26afd4fe31
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:631a31d95a04419c217f4680c272e597a61ff5728137f65ab8976de275af926b