Sign inSign up
SpiceDB

dhi.io/spicedb

SpiceDB 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.56, 1.56-debian, 1.56-debian13, 1.56.2, 1.56.2-debian, 1.56.2-debian13

Index digest:

sha256:02c02e3989b972b206d52f7d314e6758e77e13dc3712697ba4832010e34ff873

Manifest digest:

sha256:5d4c53527e520998d362e2f567bcc05509b5fd0adc84fe940d4b7e65623d1ce8

Size

26.91 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb@sha256:70f542ff4f20c3bfd554a68de1d788771fc00fa803a5476e7be3029265ddf690
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb@sha256:d3a93df0b28066ba672576621053d9bf8e3e274f5e3edb6421e7c3b969148234
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb@sha256:470272774e6f98c4476e8982f6f1fe1eeeb1e5c70654f5b8f9c7fdf0ece6d0b3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb@sha256:20fb9196621a77729aa1dea87eca5a933cf24b68ecbd69bcc119887a55dd57f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb@sha256:c888d0a20acc22db6e108564e3e0b7c21369e946915aded26b3433f29997b472
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb@sha256:c84417cc6bf8f5c5b0f277a8b48dce0959ad624d8a8aebaa0930967004cec090
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb@sha256:b1310e1f2d665b621cdd1d0b2a4565180fdad2cd95799efc1ea139e7f4d47c3e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb@sha256:8a0f874b82b2143a276a5bfd76a60b90817f7360a928b8402ad161fcd0c00fd7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb@sha256:9875065fa1f2b6e799654481217844090205b3461c1949e0b904a2dd14922ad3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb@sha256:7f7ed395c93acbcc57605863af881d64d9afa80d99bc08bd62ac264b59c15786
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb@sha256:8f642e3874dd51f5c019fedb2fb9d72684e91c7f75e45556e433b4fdf7e25af6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb@sha256:d278505d2ae125d3e3e2bb5828783fbb9dcdd95279b106d2dbf370142c9de482
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb@sha256:50f17ee483ceb8be4c14e639b8ff18afd135b05e995a629ba2c8a5af67424970
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb@sha256:9b1ff59d22863db7c14d0f031a0ec555a3b8575e3c7bd14b69d0bc80ed61febd