Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.56-alpine-fips, 1.56-alpine3.24-fips, 1.56.2-alpine-fips, 1.56.2-alpine3.24-fips

Index digest:

sha256:2bf155740f0cda0cc1c05e8972b88a0c4abba3d59851f5e12ac24888418f5446

Manifest digest:

sha256:cbfd47bbf7cd22cd8656c821e96be218ffc7bc8c05ae90280164f597e4e24486

Size

30.96 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:af50657fda74eeb76c4899377b3b892a67f1c953abeb0bee3608bda717387271
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:d27be886520e9e515adb542f096bff63e858cbe2fc5b9e3e002a6bfba2d47fcd
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb@sha256:b1dcf4e0a7eb7b8a0e4eeb7171b43d528891753032dbacb55618e14618c30fab
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:a5feb8c7b01499c804e00ab66847bef137c9b406dd5bb3a37e1cd0bd8b3d9859
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb@sha256:84ac6de020e735f81be9487982e3b2fae7322e2a3328cda140e08cf525d78b05
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:84e85af8ff8048bf85f6dcc8b8daf9ae16f5f6eb875dcd20acc25d85bf9c9e76
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:dd59ea7b7281d6dfbfd14a435a55fecf12a7f30132529e06ed10994e9b0d72d8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:916ddcb919a1acc0f2db403b342cfc4765f4eae0ef0a502438375e83d95d8ec9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:654f067c0586541090656062bccbd5e9ba3ca5daa81a546c42604e6584db0869
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:4974e27cc54732d00844a9a03e917d09a895ed7c722bf6bcaf3284d382b6e0e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:396be0a1c8fcb80e37a8e24dea6d250879b07e7f26bacb636681a6d3e8211f6e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:badb44e80483e87329bfa8939017b0f53b2d9b1092553c54e6aefa7f15f88942
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:35fab0700862a91f1b69cb8432ec6fbb2d4446b3b4a40e6289617a7cb88b2995
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:19145f4743f71bdc9a1b5f9942ec1fce8fc50bca9e36967484f59ab68b24d573
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:8ed6e7875a6c6debed185b66657820c23083083986d6b7fed342e4fbc0e531c6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:95e0789604e6395f6fec3a4087dba0af2ca82844df0b4d2f9f684a7bc83a12e0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:30d3a3e7db3931d1b1337133418acb3655e527199a619de443567b9dfa42f3ef