dhi.io/oauth2-proxy
7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.5-debian-fips, 7.15.5-debian13-fips, 7.15.5-fips
sha256:8c00837e90dd8b17dd323f37253f930ebe881eff3a88f45a37f3490cf3d12212
Manifest digest:sha256:aa24e76feb179c99feb08eb6dbb6602fd5543499f6ea18bff509b9e1e5faa79b
Size
16.69 MB
Last pushed
8 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/oauth2-proxy:7-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/oauth2-proxy@sha256:c98c874c38c38b1ad7895e7b43d3a92a9761c65212ce7731b6e7c3ff396fe19c |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/oauth2-proxy@sha256:823097c4ea54e2790afe48bd945a53f241008c63c271949b6bf0174f0398ba28 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/oauth2-proxy@sha256:546a20bae2c78875f33173afbdf6707b6c1874f02418061eff551363ccb859bf |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/oauth2-proxy@sha256:8e6568e16e9965f4113642980f4dd6bc49cbe2778c54a56b77e36d6b35931280 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/oauth2-proxy@sha256:b64b1ac71a8770580bfe7f8263ae35c6b9f3fbf1b8699b957dad0b099926a15d |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/oauth2-proxy@sha256:2f7b97ca05e612f779655e036ffe6722ec8e0ecf573c875d2a342f96d86ac6e9 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/oauth2-proxy@sha256:c734a09057a99d376f9075256b9dcb9452cdc9e5e972d9b45062710b16258a5c |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/oauth2-proxy@sha256:5ba33ece3df54f616b6c84782fd0befff90f445e045426f7ebf12623036968a1 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/oauth2-proxy@sha256:76368fbc2efbe50c02f744870913481b6885381eda11c2e4d37a36242ccd6f2c |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/oauth2-proxy@sha256:2cd7bfe802e3d5a4f262fc2055027d93766e8a26a3e68052e6940681130aec20 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/oauth2-proxy@sha256:16d35061ed419b66904b67eefe1a84afd499d1434b0687377af311d6664adb49 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/oauth2-proxy@sha256:38912e1e4ef6cbbc15de812679e79c40dfb1a53e98a543d698666cc9acbfb835 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/oauth2-proxy@sha256:655efa2cd3c45184f326d1a0b6ba9fb57105dfb00bfba5093130315f54aaafa0 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/oauth2-proxy@sha256:9505ed4fcb2ee384f1d1643f55980da18951be32b5ef6a0bd14528bf07dbffc0 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/oauth2-proxy@sha256:c68ff543e61bbd1b4b42ee68a9a6d2a4288b25edb76a7b78ae18f12cef2fd01b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/oauth2-proxy@sha256:bc7c2dd67bc2210903f505a7a96cd74d651ba3bbb9375a1afcd30b8311f8574c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/oauth2-proxy@sha256:2711042da12c204a28d947fbe4d2ede4a2ea8740c1a285d05e10565596e4ad19 |