Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.27-alpine-dev, 1.27-alpine3.24-dev, 1.27.0-alpine-dev, 1.27.0-alpine3.24-dev

Index digest:

sha256:3ab60ff19e2a70a9f8703fbacf363799efbf191e87c475c2993af5ff663baa31

Manifest digest:

sha256:abf4691b57d2dfdc8d2d1e46a8c4654e371e4fc7a96b7b77b02fe77d5711a94d

Size

38.40 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:e2a090dcff4d9e9ce98630688919dda4a5d42ed6b7fa3285e74e066071811db1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:339c5c9f5f10c4a0d9136503a58f42adfedaa14f4c3a9be963c48eee08d4d8e5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:96a19443326718c976ff85e607e45a7c36fa52bb6fe899e9076fb3cec738e594
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:f2e0951dca34958931f6dba10927bbd9b85867885eac926f10e7d29492c011fa
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:25f52ef82aaaec6c218bf7044a4be78381e43c0b2f47eb35af82c217bb5a9a63
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:863e53adc3253cea9cf72169bf5787f9e0e12551632dca6860c75543e39b162a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:d9134d89a8b71c10d55148dfc5fe6032c984ae28c10ef781bd152431912012c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:1fdbf1feff403379e5a343d51f0a4ca828e6836663dc25e7727607aed249c8d5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:4241ed68924164162dbe09a83c4ef7271d808ea79ca696f6598c0a922dd66055
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:4b722cc850fb7969dbced6fb479c1708e163b6353a40b4f6c781e84299e1ffef
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:95b30484c8c2e20c36efc2506c633da31caef1029a94fe713aaefbcd89d7201e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:2faa70f1cbf847a7fbc5618029747389b0e19b39495eb22a94dbd0b9024614b0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:5fe6911cda0f37c44fe32d98f0af48e2d14108af9f8ec835ae0cfa90bc8d95a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:f1962dfc29412d8781736d4491c19cad046908044e0e751e4f97813d6f94276d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:cf512a9a3ebeb717c320d135b47bbb671fe5e0b3c8504897141e910c20cc8251