Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.56-alpine-fips-dev, 1.56-alpine3.24-fips-dev, 1.56.2-alpine-fips-dev, 1.56.2-alpine3.24-fips-dev

Index digest:

sha256:071983c906602819e0673f3bf790b80052bffd7215a3d3e003044c84bfcfdc2c

Manifest digest:

sha256:0ed931d050b8a09a3da9adfd548b361d7b94d6b53670d2845cda7fffd65a6f52

Size

56.66 MB

Last pushed

7 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:25e194ab79d66d729da16a08a28e7955cdfd9ee8ee9756a5d16a6d898136ab9f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:3393588fcd752a2f0d2abc1c508d09394d9b800f428ff88719f5c7524854cf9b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb@sha256:f9864be4271c6150ff77f9908b8ae9d0c265db95d48438b66765f4673cb1668a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:a436a59373b79ea63106bc3e1db0cb521bcef681e5e6b635c26e9377c942ab5c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb@sha256:5513e5c03cdda044fbe353dd77eb4787531ec3e0f59987347e522e02928586d0
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:9232377ebc41765d3d1cea27d14784ddf2bef5ee9aaaafa4e54a451a9a7aec4f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:4cce624a66e13090a71f72efe57275cca9e556a64225238c8b863882cc1da4ef
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:b69c6307440c5c4aa029d3056017937d86892a11d8f041c65d03e1219601480c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:1d2ba7e4648af0428f8ec9300537b45f0f3808e63801ee27909e0e7f1ecac02c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:fabbafa24bf21136bea8deca61ae0883e8576f24e450a9b571f756a5eb17d287
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:dcb42114c63cec0c21640edf0f3a084c026fe83e2a2111bdef3749a6145ae70b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:9cb0b86d765b37048479459057a4f28e40da08c3b3b70050951ac020725fe254
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:4b6350e3e677be83e5827bb41d2b3a77a6fd46773efea3ba244a50c9dedce259
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:b5ff469fbfa97835f822efd99bf9f72faccb84d047ecd4c6b7b380ac6e91e645
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:d3fd20bfe073ecf3efe0884c75f2906f40ee3c07a046b0b37b9f5bb42c5a4218
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:9392f6b5a73a35e1c7526c54f0bace46a413849b14d1e0a008a01eb5d484aaf2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:6b6c9ad537b1c9246ec3903c7fab83b9001769f73a0230935eabf3bf9cd8b797