Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.56-alpine-dev, 1.56-alpine3.24-dev, 1.56.2-alpine-dev, 1.56.2-alpine3.24-dev

Index digest:

sha256:51b4bd1a9e55a8560b27f4f6862b1fa0b5ee20b56f2ecf9f334ea0303f5d3363

Manifest digest:

sha256:2170b85bb7a00b26b376609a15eba2d9cfcd6340da3c1569caa1ac2beba0afa5

Size

54.87 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:aa219a13ab446338e23365057a81ab20798dc4b41dfcb74d2ab2628c2fe1b04d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:101bc2007d59dacf10e073ca583ff6baa87e5e7bc59f0314f6d5659ea7e59352
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:e6397d5bf12c5dfca0598ccce3f76c696fd6bca9f0d6105a01b43a250343ec68
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:9b5bfdf8e0e1f59da1aeab411c3ed41e328dc65cc0fdbde4f5bf6dfe4a3b35d0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:155e0abdcd3799a01c8668d858b9916e7716e8bb90fa1c98778ab8f9677ddfc9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:acfb79fc584f47dd49c943ce07c4e16fab1ddba9d408649b663a47fab6fcb380
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:ed46a9906481c259db2e4874fff1d52356aaa15e57cc91464fab0ac6f5ed09f8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:5bc2a1f01e4cdcc77598395b2f00eb7a20ca513296bac46be90dedaec595d4b4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:e47f41508d4f924d6e9a10ebb9b10825415125baa48f8cd282a1cde97668f3ac
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:24b5109e44931b321586f0f75baf13c02a0d6a59643de52ba25115bc6bbde1c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:42d326dc117a36a80f7c14b52ac3adacd8b2fca6f54f84c9d193d2a46f098762
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:500f4ed6164c33574e8ebf5b4af51469f68be0993ccfbfd39829d55a077206f3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:fe1714cbfa7a1e1501499c8e3892da761e3f333834d086884cbab4a6771cc7da
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:cc188fbda6fb470a0bd325d368a754a028fcd691fe65813775164f27e84c7672
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:256b62b59b1da019254f171f4e88efda4896dee68aab2f2ca07a4e6d91d84da9