Sign inSign up
OpenFGA

dhi.io/openfga

openfga 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.22, 1.22-debian, 1.22-debian13, 1.22.0, 1.22.0-debian, 1.22.0-debian13

Index digest:

sha256:7f6234e107cf99385a803697643ed50f01f7b8fe3ab0862927d8e2465a151bfe

Manifest digest:

sha256:67179507a9b4e7c811fc78e62e4a0e503004d85d40452a4e44edad20e4d1dc1f

Size

23.79 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openfga:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openfga:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openfga@sha256:52440cf9502ced88b37ef4871bc8d124a8cc9f2abe3ec3901789effb4652f493
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openfga@sha256:6627a56336806794fdbf455e4a841463920f97064e7c37f3dd550fd70a9026cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openfga@sha256:5d68f88e5be4f2a3ac72a465ffa2237bda937247a1f0d0e01cedb94b08b8ea76
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openfga@sha256:e1f78c271f7664d62c3f5d37c3f2e18eeb3e8798d00f1075ce1205c28ce3d8da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openfga@sha256:e6dd72867b9be070c54b6f82e4d0900f9d802e536690d6821fe6c0cffea1df1e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openfga@sha256:24ea80204abb6a4b3601442d22a34690efac3c840dc9a9f64d55e4b15eb25ec4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openfga@sha256:39aea665f2f4875c51f63c4eeac1cdc068b6b39985f843dd5daad3f4d99684bc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openfga@sha256:759bc830e99def12dd4122a451c36f2d64fd169ba62897d9825d0ef820523e58
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openfga@sha256:708108f8142b496a53d37a506f7e4c7481fa358c48873fbb13543bb7bec90016
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openfga@sha256:fa1c6a275b88594b3192125dc7c66ad00c7c7bc11d98d5d16d38096f309b002a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openfga@sha256:3b238cd80d62e4c3d7525ba56e17e9a2cb354069c22dbdc0bf444dc5c441558c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openfga@sha256:ee4e3c1ad44b053c2eb4c92ed297c2e4b95696bbd047070295d9259b3a55fe69
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openfga@sha256:400c16c35706bf76d313e28a3d137fe7e7e7be7588e029f59051c8e1010a9741
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openfga@sha256:54ac52fab31b20ccff9f6ca68b37ef646f884cf9e9bf5721f32dfbd352155af3