dhi.io/oauth2-proxy
7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.5-debian-fips, 7.15.5-debian13-fips, 7.15.5-fips
sha256:9a26b2f29f1207787f8d3eeab0247781ae5855a4890e7607dce9dff3f86680b6
Manifest digest:sha256:558c93e8c0e8df89766fef1a718f5c76f2803b160ae0cef9683fd47716e3624b
Size
17.91 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/oauth2-proxy:7-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/oauth2-proxy@sha256:8ce82da5de342ac3376509d9d9366b908b84e0787446fd438f1b36f3c30988ac |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/oauth2-proxy@sha256:03f9e01b963c2715a608b1c784ef5a35d89e844501f9a42b9c3cedbf46175609 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/oauth2-proxy@sha256:b17b736f3ed22a65d137833c5306665e5b55534307d63d5084817d55c5010948 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/oauth2-proxy@sha256:53124ba2ee161983ea0daa87e7b3f30b06f69a7baa357cfed7f46e9e2f32bcf9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/oauth2-proxy@sha256:f85a3a92c8a043aa1f1ec89ba0b2bc5bc9343f30b8611159d83333501d2ce7f2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/oauth2-proxy@sha256:e54c5e5cab7484ff00bc93702646a50bcccaf94334933cfc3db09465bab73101 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/oauth2-proxy@sha256:1a2575ab6eb490010620dc9660bdd2edbfffa68bf6b76eba122bb83244c0331b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/oauth2-proxy@sha256:008f07d0f196296660311024d886358a41698d7a74c2b6c9917b299effe73682 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/oauth2-proxy@sha256:c47e575c3145db64da8b40934bcd404c8bf442b9bef6c92f3168dd6a6e390119 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/oauth2-proxy@sha256:b59ef0f7375cbd29a2ca3f4b630b827584e1f876ead8f0115478005a3886b932 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/oauth2-proxy@sha256:83753130744f76f96b68e886de71aa7ac45ed69591bcfb362ae75479a79d4e59 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/oauth2-proxy@sha256:7fdb251b813780ebcb38db33c6fd56cc3f93eb58378e340e9b2c8c77defcece2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/oauth2-proxy@sha256:676a4b5a314c1fffde4524291ed80afcf0c8682295f5649f1fb14d1a9a9ea9c1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/oauth2-proxy@sha256:5e3217637dd604d8daacdf58645611588022feffef8b4a2b5751a2aba90dd295 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/oauth2-proxy@sha256:e9f72325b92d49e81c3a9d28007b34eee897bf1dcacf6f2416e42bcec92ad317 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/oauth2-proxy@sha256:fa9412d81f79568e8bba56ae0cc05418e7ba92eaf1c01db8cb729b4e76688e7d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/oauth2-proxy@sha256:5a9fcf26c4786dd4bb2ed6d0a7a66ff2d87ea5fc0826762a9f1aaf3997a9041b |