Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.27-alpine-fips-dev, 1.27-alpine3.24-fips-dev, 1.27.0-alpine-fips-dev, 1.27.0-alpine3.24-fips-dev

Index digest:

sha256:c72a6b6384e851153a257e0734262ad1548e2e1381ca3dea91b786d6322813d8

Manifest digest:

sha256:a5eefa138a2a07d9f16cb7de4d710d6f35e8993c3522f85b7c822f7efad31417

Size

39.24 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:64879e74073d35b52d7e1657874303a1c4573422edb02bc543413fab2452f7e4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:4e0d7fc3dfd25142e26005231aa187ccfc08da11876c32d4525321cc69db875a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb-operator@sha256:9d155be3753a8ad0be0e1eb8924cf8cde7c94b21c97339e1b38760b458f4845b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:4dda3d90c6a9ca92fe36ca357fe7da879e6c2475a99fa2c073cb4f87650de30e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb-operator@sha256:8ca4c21f30fef629a5160c804bc16b63c8dea1e71dfdc54d8721563ef6086859
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:542856194992d5dc6fcc1237881bfb8581671c00cd32ef6ba9c38f78413d466b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:9ba458a38f519861bafcbc7b32d72025f95e67c14506ed1da7651f9f15a0a9ff
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:9fb40feeb2a1678b90266169c0cf532bc5c56ce69b328ada5d602bb01fc96d67
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:a5e5d9e7de71f004e2192d580f1d58ebd7cda3a07f10f5a78529265f41c748a6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:f1f4fdea2314331b51056511078e3410834667db4bfb6e134da66664cd10c0e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:980f2a5497f959a00e0b49f98c9bcf212ff72fd896e03d1c39079448d2265fd1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:4de49726728f2c44317b7a479d483c07ae83face733f4b319c3fadffaa7f38bd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:759795564afca36fa57f01c4a02228cb53634e51b5c25dfe597946efd9d1efc9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:bde291df37535a572512a44d341589702ab8f71e74f3f7f6bef0d116ce897060
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:b8cdb027fc80269150a0a58e91ce730cb5e51f4ac9f9503b0f4d2655b655ae6d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:79a395926ccfd3fe46ec70bbb113a33886533b049eb146c39b6fd5923add91c9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:d2890cbbd7f9c9a242fa1b1cba210baa24ca641b7a9b98d38bfc006a00b37c51