Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips)

CIS
FIPS
STIG
linux/arm64
debian 13
Tags:

7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.5-debian-fips, 7.15.5-debian13-fips, 7.15.5-fips

Index digest:

sha256:8c00837e90dd8b17dd323f37253f930ebe881eff3a88f45a37f3490cf3d12212

Manifest digest:

sha256:aa24e76feb179c99feb08eb6dbb6602fd5543499f6ea18bff509b9e1e5faa79b

Size

16.69 MB

Last pushed

8 hours ago

Vulnerabilities

0
1
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:c98c874c38c38b1ad7895e7b43d3a92a9761c65212ce7731b6e7c3ff396fe19c
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:823097c4ea54e2790afe48bd945a53f241008c63c271949b6bf0174f0398ba28
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:546a20bae2c78875f33173afbdf6707b6c1874f02418061eff551363ccb859bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:8e6568e16e9965f4113642980f4dd6bc49cbe2778c54a56b77e36d6b35931280
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:b64b1ac71a8770580bfe7f8263ae35c6b9f3fbf1b8699b957dad0b099926a15d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:2f7b97ca05e612f779655e036ffe6722ec8e0ecf573c875d2a342f96d86ac6e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:c734a09057a99d376f9075256b9dcb9452cdc9e5e972d9b45062710b16258a5c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:5ba33ece3df54f616b6c84782fd0befff90f445e045426f7ebf12623036968a1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:76368fbc2efbe50c02f744870913481b6885381eda11c2e4d37a36242ccd6f2c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:2cd7bfe802e3d5a4f262fc2055027d93766e8a26a3e68052e6940681130aec20
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:16d35061ed419b66904b67eefe1a84afd499d1434b0687377af311d6664adb49
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:38912e1e4ef6cbbc15de812679e79c40dfb1a53e98a543d698666cc9acbfb835
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:655efa2cd3c45184f326d1a0b6ba9fb57105dfb00bfba5093130315f54aaafa0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:9505ed4fcb2ee384f1d1643f55980da18951be32b5ef6a0bd14528bf07dbffc0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:c68ff543e61bbd1b4b42ee68a9a6d2a4288b25edb76a7b78ae18f12cef2fd01b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:bc7c2dd67bc2210903f505a7a96cd74d651ba3bbb9375a1afcd30b8311f8574c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:2711042da12c204a28d947fbe4d2ede4a2ea8740c1a285d05e10565596e4ad19