Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.56-alpine-fips-dev, 1.56-alpine3.24-fips-dev, 1.56.2-alpine-fips-dev, 1.56.2-alpine3.24-fips-dev

Index digest:

sha256:d7034f10aa8259e0b22f66d284666d938965e459e65cfe642cc8bc3a04f76fe3

Manifest digest:

sha256:d6ce36b26eacd7efb2dbcfce7444b479075fa31064fc71bf7e415cdd97e3a0a9

Size

56.58 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:34bdd00c2b581327ae5506c4e8628ad3d7a765868fcf3a8612c6ff2f2bd0b015
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:7c5927562f17adedfd5cb39ad7a7c5e72f0cd489d9c74fa3b34fdc8db26309a4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb@sha256:9ab6517e6d916506a227140b248e4640d7be1551db3ae3bba1ed0f4f9b64152e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:8747b581c1f7e6768638b2edcfc80854f7909f6696f00c0c3ad4104c88fa0abb
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb@sha256:375ed7830ccc2a340e4e9b174d13fd33aea149d1b8fbd7cd45d0f988850eed6e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:ece5c2cd493b42a66e6aca6eef2c59ad9b3baee37ec389d182818fe753350e08
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:0894e1f0ac808dc4162e7b68ed3c34b3e35e217df7c5b062594a05eaaecd286d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:a58c30e0f9594964b2107075de0acfbd08a520943d031fab02a1c3b2fb75e047
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:ec2394a5605294442c269ea323242e6a51c4a9ad5633df704f869e7ec810674a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:a7293d92ce0db5fb02facfd478993ea6bcb6fe829ddadee555b95796356eb778
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:20dd8e52b2c7f023abb1bf3759e88fc2875a2f62e867104523fa4e0c1a9cb11a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:e046d4fc4c4b89abbc46ed8d53dcca733b24fd2cf2460711b09e84a527cdbf39
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:08a2b6f35ccb363177ea5046b0de61a94ceab869e909775cd7f59b1d4d9e44a0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:620d8acced25d2f31f6a465cfcc0ac491858e4749d97a90774942d78ebafcbc2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:b4f030a633c764576ce9ba6872b042f1a861cd5c758adceb5544a3450fb34075
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:7369633fb7206fa09de123ff5e36043ad2c2ab899e286b54d8dbb006365f91e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:6ad0e79403de44ca6f493bb861453c287c65c75b89d74638cac946fd58aafef4