Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.5-debian-fips, 7.15.5-debian13-fips, 7.15.5-fips

Index digest:

sha256:9a26b2f29f1207787f8d3eeab0247781ae5855a4890e7607dce9dff3f86680b6

Manifest digest:

sha256:558c93e8c0e8df89766fef1a718f5c76f2803b160ae0cef9683fd47716e3624b

Size

17.91 MB

Last pushed

5 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:8ce82da5de342ac3376509d9d9366b908b84e0787446fd438f1b36f3c30988ac
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:03f9e01b963c2715a608b1c784ef5a35d89e844501f9a42b9c3cedbf46175609
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:b17b736f3ed22a65d137833c5306665e5b55534307d63d5084817d55c5010948
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:53124ba2ee161983ea0daa87e7b3f30b06f69a7baa357cfed7f46e9e2f32bcf9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:f85a3a92c8a043aa1f1ec89ba0b2bc5bc9343f30b8611159d83333501d2ce7f2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:e54c5e5cab7484ff00bc93702646a50bcccaf94334933cfc3db09465bab73101
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:1a2575ab6eb490010620dc9660bdd2edbfffa68bf6b76eba122bb83244c0331b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:008f07d0f196296660311024d886358a41698d7a74c2b6c9917b299effe73682
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:c47e575c3145db64da8b40934bcd404c8bf442b9bef6c92f3168dd6a6e390119
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:b59ef0f7375cbd29a2ca3f4b630b827584e1f876ead8f0115478005a3886b932
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:83753130744f76f96b68e886de71aa7ac45ed69591bcfb362ae75479a79d4e59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:7fdb251b813780ebcb38db33c6fd56cc3f93eb58378e340e9b2c8c77defcece2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:676a4b5a314c1fffde4524291ed80afcf0c8682295f5649f1fb14d1a9a9ea9c1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:5e3217637dd604d8daacdf58645611588022feffef8b4a2b5751a2aba90dd295
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:e9f72325b92d49e81c3a9d28007b34eee897bf1dcacf6f2416e42bcec92ad317
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:fa9412d81f79568e8bba56ae0cc05418e7ba92eaf1c01db8cb729b4e76688e7d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:5a9fcf26c4786dd4bb2ed6d0a7a66ff2d87ea5fc0826762a9f1aaf3997a9041b