Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.0-debian-fips, 1.27.0-debian13-fips, 1.27.0-fips

Index digest:

sha256:f6659951bd97ccf0bd05e172664a6dd302fc82db350ae602650438b03b29b7f6

Manifest digest:

sha256:938b596c1df6a2a2d6a9ddebe78a06b2e73d6f7a76a60f938e7de6db407e9331

Size

26.13 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:d2bdbe32c473db6225622a6f2ef548d835140dea5e1c6a8449727408c582795b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:c314f5e0e267183a5d236e76f696784f0f64dda11be7830f2fd93d63b2235223
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb-operator@sha256:5566c1870d8550c9e2f0bab10cf56690dfce577b3cde3af59ad8c999ddf3038c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:e871448ae88013d3e7f2e7772f506d6e6927c17cd8fee8defd9753ff3389a5d4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb-operator@sha256:39c7e5d80335c3c4732a5c9f41576db0134fbfa59585946d423dfd204724ef54
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:403b3eaa868b302ca24f798498aa95c1baec4dd8f1beb968c9c2085e20e35632
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:7d9d57faf18d4b7478cf81f390f4344c6111aa910c3d2d0a8a3c029a9424ae47
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:f032509596d133a0fa4bf904510f36515a262a0d55d67b92dacb0bda1b07bcfe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:ed800fe10d7a154f63354f5a7baa2accca29334f7541a33d104c04048493a641
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:0e2617ef3b368a2013f68eb81966ed8dc063f9f548744fe4c80f162f543f9d9b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:5227644d3bb3bcfdbc3c2fee25d5b0fb467dcf8ee301b96fd83ea4782765576b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:f2beb0214310c97b823e7e8ff4be5e50fc8c496cc3bdc5ae72c9e5d835dae999
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:69dfb82dc4463f8aa27f9d72a26af6595cae5317d78de3eb27f70cf2edb9e8e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:17bc3a19388b3b782517a2fbb7c701530a2791fcab63393cd73ad666c1971b45
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:3dd0204a51c7853020e871cb242cb07259507e3d96892e5fab6e141bcd07d387
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:740112d73532505395db2cf6f48c3ead42433425db2a987f31c8a57567cc2280
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:ae925319a295edff94240ecf3c4bd2b554c7c2ec18b8eb7760e326c1413f8495