Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.0-alpine-dev, 1.27.0-alpine3.24-dev

Index digest:

sha256:7efa8905b7e27c6f3bd36e8b04ddf9fe5ea9c8a9db5dd2e24dd3b7dc12f52c50

Manifest digest:

sha256:7e7d97d9cb7c57731b914ae3958bf3b21b3f4503b1eb0e0e4d7577f26cdbdbca

Size

38.40 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:ca3d5cde96eaa09da8ed32c0b00ad9ae32c5a670e1728291a0598f9bac431048
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:861aa99419a53a9f3ef9879c9f03bf58c8299687b745375a1db3a3f1dd4a9f77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:2e8fa4673e0c7cb82d8d3876b4cb378b72525b75ef92dc66f50400a6c4caccc1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:d8294c782fd4568a4c5b17a5ee534f95d9946006ffd7e52a7c79aeb0e3150b5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:3f471d7a234bd5881bf85fade6816e4da1e6b25896fd43b8cac850c85f4291c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:d96c21a70af3031145be9c84fa9917afb07b1434a3a95ba06bf848d0b4bd0880
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:dffe16552c39bcd4c03f6dc7bd7a17e88514ab79a0b67b12c29d57b0134c81a7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:5e575eaf71439ba53610aacf4e611bfef8abb8833c6ea647441c44ffe85abcf9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:ec8318d6b05b21aa0f1091ae38e306fb36c08ff671553b8eaac2b674f3bf4f19
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:562fce3fe8b8791341349912f820d36c7c3572a026691f2f6e12035f118a8b90
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:cce788f705185de56119f112d055ab7132b74101ea500c724cbce4aa3aacbd81
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:d1bc7f702822418d5834801dfe06b24976c9174cddac6db169c418ecf467b2e3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:eedee18cd4c8b43a761a97f14d4d32c8158445a07b9842476c4e3af1916269ca
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:714a47b7a39e0ee342afcd85bea3db7957000e158bbb0b2d2314b4f776fc62a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:0bc779282507a3abccc44303257640ea15e0f32a884a5b2220317186647ad3ac