dhi.io/spicedb-operator
1-alpine-fips, 1-alpine3.24-fips, 1.27-alpine-fips, 1.27-alpine3.24-fips, 1.27.0-alpine-fips, 1.27.0-alpine3.24-fips
sha256:34ca1b76d224bf572b0744c15f7b3b9f842f077201904f39211485f0a9953bb9
Manifest digest:sha256:7cbb6f34765569f7f4e6b6791fcd351f44ad89d7f9214d49052a62a27847d129
Size
21.08 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb-operator:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb-operator:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb-operator@sha256:bcd0445534fe57143d9a9c1fe67e2eb2cce668424653315c81e0d0c4f49f9982 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb-operator@sha256:075939257d8ad15cd7ac605f3a533b2549a59b977c41103bed87068738487c41 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/spicedb-operator@sha256:522f19b0226730f259a06109e1f90ee02a9f4d2b4a1003d0ce90f5d974b11cfb |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb-operator@sha256:830308a44855d8850c676fcad9671768cff6e6c75756befb5fe905c97d03368b |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/spicedb-operator@sha256:ae03118d4bbc695769ecd0052f6a7ff93602a894debd1593a2ae10ab0ad85b55 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb-operator@sha256:fee5f17077c29ed7b374dbc67932f3d628617a52e911d1e7c1819e862a6517b3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb-operator@sha256:b79ffdccd7109c91f56c201d534b7f943d3b135e1e8dcee5ef643fb973ab22fa |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb-operator@sha256:533681dd3111c9ec9cfd24574218483973266734e37f06f7a1b32030dedcd13c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb-operator@sha256:c7bb79fb966699f59c1bd1da1af9ac8de9cb950accc1c5fb6b204d66010a057b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb-operator@sha256:f4785b3d649fc841c12bfb1caf68b6ba15a73f6b6f491630fe0bba380e4833d8 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb-operator@sha256:37ef6448a85422b7edc21b626f09c6fd185a585df5a05c96572f28156cfa7068 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb-operator@sha256:a7a2fe6e61b2883c13b1105e6e381c4fe300469be0f80fa8742296db1340db2e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb-operator@sha256:7f3825e9dfcfe13ea17a753f3267320fced5a3ab553a0fe1c2174b678987d9a5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb-operator@sha256:951da12ef41932a71ec0ed525432a83f1af8e8bb3c2d65583e697e5275450f29 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb-operator@sha256:ef71194de5128b286e3fcd130464eb99198e4bac869ad4d153fcb7bf0df51b23 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spicedb-operator@sha256:c454a1d7011e68424768b2451e71dbb2bffc070ac432d10244188aee0c192a51 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb-operator@sha256:3385648878a42da42491f534969033939f2dd1256d0b197899c6b7aa2b07cb01 |