Sign inSign up
OpenFGA

dhi.io/openfga

openfga 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.21-debian-dev, 1.21-debian13-dev, 1.21-dev, 1.21.0-debian-dev, 1.21.0-debian13-dev, 1.21.0-dev

Index digest:

sha256:2dfd4792b5f9365866d45ad0d401c8df042b730fc68db3ff93dc92fa9194fe93

Manifest digest:

sha256:8bd8c2042f73d288a07f9a996d475c5054f6cc9dd3133a809d22e91fe94ddc3a

Size

63.77 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openfga:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openfga:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openfga@sha256:b5bb25f9c16eeee141fdb6d100b6f76f6a721e80605e9492654c5706c61ee3a5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openfga@sha256:41fd5a31de9ec25acb5cc65f7d83ad3e32d4a085368840afb148ed35859b561c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openfga@sha256:157a6a6caf2dddd79dfee30811583d535df000dbeee79d1102721a518d99d400
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openfga@sha256:ae9f174ec67816fef8013f1eb5bd43560771068c98533d688509f766b904edcd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openfga@sha256:4331a3eb0c6f6c5357ea0560c27052ba9acdd4777e6b865762568dba885caf6b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openfga@sha256:b4f430ff5dcf8ea41fef28abb1734d3fe0d48a476dae11e613c6426458c96f34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openfga@sha256:a133208da8ed7dbe837f186f23687a3af6293ca7d57670d70d582eb7ef75b354
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openfga@sha256:461cf5c04c7b2617f28d88d4cedcfb87c253302e726b829525a3123ed814bb58
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openfga@sha256:933ef7715d8f0b434aa3078fc335e6a5c1e77d7af3f95a6a1aacf34e6f4e4017
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openfga@sha256:2ce620eb54626469751c9ee0f724d12ad68c11af082225a76b95a02ae0ade8fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openfga@sha256:42569c27f848b8cf0fc06401512bc0585864eea506c19aa73183d4ea00934fcb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openfga@sha256:c882d7ea786208c8f42984700561b28690f30346587e8debd0bde975e9ca8837
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openfga@sha256:a202b5d37494040c6fd81abb6ec90357356a99c462e7cb53eeae332b75ca7832
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openfga@sha256:2640e811280b800d4a5c806bb5a3bf25964662514bf0a504535749568f814283
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openfga@sha256:409fb1944811e097a5714fb88bbe75fa51c2ec693c52f1c6e71ae5223668f367