Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.56-debian-dev, 1.56-debian13-dev, 1.56-dev, 1.56.2-debian-dev, 1.56.2-debian13-dev, 1.56.2-dev

Index digest:

sha256:50ceb9d650130155bed7187fd28c5f5dff23c5ac3465759d121ce8754f543340

Manifest digest:

sha256:447bc72933b983b316edb84f4bc69f0a28a732c0db78adaf3b09bae09630ba3c

Size

74.54 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:8d27c2f7879bf72d343df96e7000e938cf893d7f03432b357413040b3c6c7914
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:bfa6b1594fce2859bfe88784ece18d142919e88408aaeb3e029fb1c7ae16a23f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:a175a15c1885b87dac5ffcdb6904c77842d5775c8bfe848406f198f6991b993f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:b856f782a7daa2024a05cb8f3806c26e47f3fe6c65f323657dc4151d29dc1a70
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:41566817eba5387c5abf9e4aedfaf6f0de960ee570dde463f7cf8d474fc3dfc4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:d268e6a7c9734cb61c24d3c8600fe87e3fccc0ba8179f0a1cbaa80801d8dd1b4
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:71885a99f654f3b9af1dd0d577a3285e2a41e83431692d077bbb9f9cb3a5ce5d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:da61e78c42228f07e72ff855372b215d2881beff6a82b8a854bcb140a73784b3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:fd24e22dc9668155e3c22e77cf62b11c7f8bcf042bca843fb187779e8d772558
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:73a74236c7a1440bbf652b8dea20ca46cd9feffdc6de3651bd3336e3b7c634fe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:896add71d46df80145f88e1ffb1439ea52efb1d3530e3d26d64715dde646ea33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:9c7a032de7bf79311a712cc4b982b7317e028c844bccf1c5f5fb8febcd3c6b15
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:bcac3bdd3587096f344a064209fd13b0b10ede32428dbdbce8735135866e5b43
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb@sha256:493d70c1a26a33f623d4ae406d8ec86f356dae792868c2436ec3cc8d1ba7f6fb
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:8a30ef5765645b081a99486ece3326f9c307f55f63f74b9f9004cd3fbc40e72c