dhi.io/spicedb
1-alpine-fips, 1-alpine3.24-fips, 1.56-alpine-fips, 1.56-alpine3.24-fips, 1.56.2-alpine-fips, 1.56.2-alpine3.24-fips
sha256:2bf155740f0cda0cc1c05e8972b88a0c4abba3d59851f5e12ac24888418f5446
Manifest digest:sha256:cbfd47bbf7cd22cd8656c821e96be218ffc7bc8c05ae90280164f597e4e24486
Size
30.96 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb@sha256:af50657fda74eeb76c4899377b3b892a67f1c953abeb0bee3608bda717387271 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb@sha256:d27be886520e9e515adb542f096bff63e858cbe2fc5b9e3e002a6bfba2d47fcd |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/spicedb@sha256:b1dcf4e0a7eb7b8a0e4eeb7171b43d528891753032dbacb55618e14618c30fab |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb@sha256:a5feb8c7b01499c804e00ab66847bef137c9b406dd5bb3a37e1cd0bd8b3d9859 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/spicedb@sha256:84ac6de020e735f81be9487982e3b2fae7322e2a3328cda140e08cf525d78b05 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb@sha256:84e85af8ff8048bf85f6dcc8b8daf9ae16f5f6eb875dcd20acc25d85bf9c9e76 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb@sha256:dd59ea7b7281d6dfbfd14a435a55fecf12a7f30132529e06ed10994e9b0d72d8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb@sha256:916ddcb919a1acc0f2db403b342cfc4765f4eae0ef0a502438375e83d95d8ec9 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb@sha256:654f067c0586541090656062bccbd5e9ba3ca5daa81a546c42604e6584db0869 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb@sha256:4974e27cc54732d00844a9a03e917d09a895ed7c722bf6bcaf3284d382b6e0e1 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb@sha256:396be0a1c8fcb80e37a8e24dea6d250879b07e7f26bacb636681a6d3e8211f6e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb@sha256:badb44e80483e87329bfa8939017b0f53b2d9b1092553c54e6aefa7f15f88942 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb@sha256:35fab0700862a91f1b69cb8432ec6fbb2d4446b3b4a40e6289617a7cb88b2995 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb@sha256:19145f4743f71bdc9a1b5f9942ec1fce8fc50bca9e36967484f59ab68b24d573 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb@sha256:8ed6e7875a6c6debed185b66657820c23083083986d6b7fed342e4fbc0e531c6 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spicedb@sha256:95e0789604e6395f6fec3a4087dba0af2ca82844df0b4d2f9f684a7bc83a12e0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb@sha256:30d3a3e7db3931d1b1337133418acb3655e527199a619de443567b9dfa42f3ef |