Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.56-alpine-dev, 1.56-alpine3.24-dev, 1.56.2-alpine-dev, 1.56.2-alpine3.24-dev

Index digest:

sha256:982238d2a64ec29b965a1205fc7a7c4097642195f42c5d27f2d1267fd9cf347e

Manifest digest:

sha256:d0d4e31571b9df0c06c6f31caad1c9a0d5cf0bb37edfc2ced7850d5275facfe3

Size

54.97 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:62d0da75a6e807910b76db61583f4bdd43eb588cf294eb934a0b8460c3394036
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:7fb5f9a9c3689b1e45bde425c0feb9c9770059005df0b95e34737c0447825394
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:ac53ce2b57011859fa5f59a7578d2dcc246d76c3678d1ed446928d1e15671c0e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:cb47243799ba651c0a23e42d973db85dfce4c26077841d7ed3f7f3bb3781a31f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:5e1cd3e24dccc9eec1d2d7fb42d0978ed3961404da4283d936bab438bd48a0da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:d7532adfec5ea26c01f38a4403f739755ba8ee8c8f3d07d258a7b893c3ca9c2b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:5fdf1361e1cac9c83f4bb30e457d5661d22530eca84bc135948ee2bcad98df01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:83660f59dba98d843df144a3212f437c8afb4a9e0f316d320b95f3c43cc78e2e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:8f3490b64122849b0b8edb88e452d93cdf847ea18b0bac84d7f3fa865fc1bc77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:6e76bf830166d52f476c630aaf7437e3e0d503f8d9da13316ff7ada58c99fbc2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:af23363e70a58c9ed2cf728e3ebdb94383e4e139311e27a4c89d6cfb4698b5d7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:e970ce8a6fc4141ebb117c62c57ed190e17d7bc098ac15081c6b493f857a716a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:e9197dea4298182a844e6e63614421bbfc8cdf7cf95ce1a03af6fc5fa36c5b3d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:6d73cecde1e7a80a40b6ceaf7da91b03d1e0f3fd55fe911c293e1fb5b14e530f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:fe02389a12f3fcee95f72bd0d1e3f61ef570023c2364aad207d9cb64f931613e