Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.56-alpine-dev, 1.56-alpine3.24-dev, 1.56.2-alpine-dev, 1.56.2-alpine3.24-dev

Index digest:

sha256:d6af50e5beb012660e751b0a5f70a07062739786bdc5cb8f6446f1fc5e1428c7

Manifest digest:

sha256:d3203355d076befac95fc4ca3f3d2e3e4cd69faa512557e415be3adc08361049

Size

54.87 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:ee69917516ef45483d0b8ef64f3e6ea7311a4925b6d3fc49df620d4953412d72
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:587e54bdbc627fdddbda63b340322a99bb9aeb7efad3a0f070ede59e12c1f853
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:7bb7f586acd845de17a72eafd03e3bbb6886184cd34690ebcc21d55977c34134
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:24abf692621344d48ee0f0973f80b5912554c315ea1d54fccd27c3414edc74e2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:3ca5bdec20231b562335246be8f7e4a9454cc1fed0222006561e4834672d5831
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:5022d793a471cf59a5b4f3a1ffdb9dc82fa81ba8bd5a9f9307623bc37b54601b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:d400e8de0bfce438ebca1e69fcf94816a57803ca402081f19b648be542c89d2b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:9e3c9b25904d1a0346db2b29598754c3e244a06439e9986262cd0bdb33f9432d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:deced5db8755e2651ba77ad725339bf4ba438f1c879c8f43223c8edacd0d3217
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:cafb4c1ab8993ab0040b4c93c2f159da9a370bbd3ba2268ed37c14724d023f09
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:4203ca1a459e3a291d76a6861b6795080e84ca0b17184a0f933a2fce0359db03
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:3b5e23c5553a19625e95ebcdd82f4fb28a36f48165736e843036fa9e22ac3f18
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:5bc8659b16335d9228316f9b824d6dd3551ffa4a3114c53d4e9650ea2121bee1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:861e99422ebe5116b2ada1d683a1326204b2a09c0af215a52d6966742ef2a9a3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:e6c17761267d4f2743061ec84ecad3d6a91192e8792f31f423fd39056b6587e5