dhi.io/spicedb-operator
1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.0-alpine-dev, 1.27.0-alpine3.24-dev
sha256:439b07577c3c9be0062585775449fd1ccb0f9ed6e9f5558425744eb4539bf332
Manifest digest:sha256:7542dc0169aaa0f50bc474a0c2cfbea4734467ed98d9e9ce659e0e68043d72ce
Size
38.42 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb-operator:1-alpine-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb-operator:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb-operator@sha256:441893c76bdd5ad8ee2c0f8e4c4f6d5cbc2cfab058f9396c6f0dcb13e09a131f |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb-operator@sha256:a0315940004f36006ad315aa6701f58bf1ae8caab540be223ec11fcbc5b51f27 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb-operator@sha256:59c28ec2e12eeeec1ea97525520c1fb196f204cb61a147de9a5408497924f604 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb-operator@sha256:db34f33e0ac9f92f7399982986851779dc4fd6855d61ca6a3ff058076ff9c2df |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb-operator@sha256:9065fac72302c3a26073d72cfaf12b81b70c88c25abc21f442b91c83b9a8860a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb-operator@sha256:fd6b72cf0adede2989125c7c4312b7709ea483f308b7429dc454e87aed601c57 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb-operator@sha256:8a44644ceeebb1cce92ebfc00c15b6173cfbc4a896b99141ade3246464355797 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb-operator@sha256:613f8934db2d02b0cce00f31177e898bf41d76ae876995dec0a36e2ef70061d1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb-operator@sha256:9bc6d01726aa7b1a2fc0b96fbd336a2a3ac05f001003dd8830963b31f5209d5d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb-operator@sha256:10b6d20b834c8ab720dc8d4af6c9d2067857103336f14edf93ac4c5981a1b404 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb-operator@sha256:265fc3a611da142e89a1f81a29c51e9cdcd1c12824740e52691aa2cf9fed2676 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb-operator@sha256:3faab9e1a1110392f87a0911eddbd1ca2d3286a7fbe579af398a717fe7d8e616 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb-operator@sha256:2b90e891faaa81a1d249fabe07c831d24eb6e13535f2447ac9ad169a0a3a941d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spicedb-operator@sha256:84ce0ec16c13ee2cd74c3f04531c6735a93738036dfe2e33b70204647c752871 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb-operator@sha256:1562448244b25f0ace2cf32911e99fe73093e759122640960c6cb0948cde5091 |