dhi.io/openfga
1, 1-debian, 1-debian13, 1.22, 1.22-debian, 1.22-debian13, 1.22.0, 1.22.0-debian, 1.22.0-debian13
sha256:7f6234e107cf99385a803697643ed50f01f7b8fe3ab0862927d8e2465a151bfe
Manifest digest:sha256:67179507a9b4e7c811fc78e62e4a0e503004d85d40452a4e44edad20e4d1dc1f
Size
23.79 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openfga:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openfga:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openfga@sha256:52440cf9502ced88b37ef4871bc8d124a8cc9f2abe3ec3901789effb4652f493 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openfga@sha256:6627a56336806794fdbf455e4a841463920f97064e7c37f3dd550fd70a9026cd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openfga@sha256:5d68f88e5be4f2a3ac72a465ffa2237bda937247a1f0d0e01cedb94b08b8ea76 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openfga@sha256:e1f78c271f7664d62c3f5d37c3f2e18eeb3e8798d00f1075ce1205c28ce3d8da |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openfga@sha256:e6dd72867b9be070c54b6f82e4d0900f9d802e536690d6821fe6c0cffea1df1e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openfga@sha256:24ea80204abb6a4b3601442d22a34690efac3c840dc9a9f64d55e4b15eb25ec4 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openfga@sha256:39aea665f2f4875c51f63c4eeac1cdc068b6b39985f843dd5daad3f4d99684bc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openfga@sha256:759bc830e99def12dd4122a451c36f2d64fd169ba62897d9825d0ef820523e58 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openfga@sha256:708108f8142b496a53d37a506f7e4c7481fa358c48873fbb13543bb7bec90016 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openfga@sha256:fa1c6a275b88594b3192125dc7c66ad00c7c7bc11d98d5d16d38096f309b002a |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openfga@sha256:3b238cd80d62e4c3d7525ba56e17e9a2cb354069c22dbdc0bf444dc5c441558c |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openfga@sha256:ee4e3c1ad44b053c2eb4c92ed297c2e4b95696bbd047070295d9259b3a55fe69 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openfga@sha256:400c16c35706bf76d313e28a3d137fe7e7e7be7588e029f59051c8e1010a9741 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openfga@sha256:54ac52fab31b20ccff9f6ca68b37ef646f884cf9e9bf5721f32dfbd352155af3 |