Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.27, 1.27-debian, 1.27-debian13, 1.27.0, 1.27.0-debian, 1.27.0-debian13

Index digest:

sha256:27168eae8782d1ad6d357a4c0ba0dd8e5cd4f81fe49760af3e0ec7827bf42005

Manifest digest:

sha256:ea846b4d22fe5c153e4c912648bfdb06bf491ca71b34373ae48cc52432b49fc5

Size

17.95 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:b58e8dbb5d40e6f9663896b6ea8ed1eb978dee0b80224e3b080731ca67d777a3
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:e202ff5a38abba1c07da57cc24307b7cbae5d53dd62914e2d34b72376a70c416
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:235f628d3fd1fc3627b9944dbdab74c07ba1628bc5970fbe4dad48bac19bdf1e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:162abe24dc8f2cb0df1286ce3cd7f01f45a32f82a08b217e00179faf348a93b7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:69c6689f3fad0f4f760731da4bb845e2f604c2ef3109536ebf3f52d8310fe4c3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:227fba0c439b56ad68d4321f9d9e2ddeb4175028e0241efcac24e3e812a9ad8d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:c255c3efed8ea9c21265f5326f4d1b8b7438616f9803196e7377d69c2d704899
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:b06abcb9bdd8c5b09ef7f12a906b9cd9025cedc1053b39252897138b4954c8ac
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:9ac7d20edd28da96a35ab68c3a41e8517aa50fb87d60d251ac18409367af5825
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:f4e5bdf275fbdec2c126bb29f546514aa85b99343c5e1751e786f316904e0443
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:c766391142f2a1eccadc6521c5b57ff93824bf797ef6ebb2f17edfabca099338
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:ee3d31f0bb25ea484018e1163fe30a5480ff37b7787d78fc3f3bcdc9639a0118
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:11d3a4c9ddfaaea24ce1a8cb7f65653faff9b9a1dd4b90598a6731b004110fba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:55b3d4af0df82c610e94136d21748b5d2a000a2aa4116a659d0daf43d2138996
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:c51672e576528c53453564875eeadb9ed861325ca8c69947544656fae61ab6a5