dhi.io/spicedb
1, 1-debian, 1-debian13, 1.56, 1.56-debian, 1.56-debian13, 1.56.2, 1.56.2-debian, 1.56.2-debian13
sha256:02c02e3989b972b206d52f7d314e6758e77e13dc3712697ba4832010e34ff873
Manifest digest:sha256:5d4c53527e520998d362e2f567bcc05509b5fd0adc84fe940d4b7e65623d1ce8
Size
26.91 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spicedb:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spicedb:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spicedb@sha256:70f542ff4f20c3bfd554a68de1d788771fc00fa803a5476e7be3029265ddf690 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spicedb@sha256:d3a93df0b28066ba672576621053d9bf8e3e274f5e3edb6421e7c3b969148234 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spicedb@sha256:470272774e6f98c4476e8982f6f1fe1eeeb1e5c70654f5b8f9c7fdf0ece6d0b3 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spicedb@sha256:20fb9196621a77729aa1dea87eca5a933cf24b68ecbd69bcc119887a55dd57f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spicedb@sha256:c888d0a20acc22db6e108564e3e0b7c21369e946915aded26b3433f29997b472 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spicedb@sha256:c84417cc6bf8f5c5b0f277a8b48dce0959ad624d8a8aebaa0930967004cec090 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spicedb@sha256:b1310e1f2d665b621cdd1d0b2a4565180fdad2cd95799efc1ea139e7f4d47c3e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spicedb@sha256:8a0f874b82b2143a276a5bfd76a60b90817f7360a928b8402ad161fcd0c00fd7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spicedb@sha256:9875065fa1f2b6e799654481217844090205b3461c1949e0b904a2dd14922ad3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spicedb@sha256:7f7ed395c93acbcc57605863af881d64d9afa80d99bc08bd62ac264b59c15786 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spicedb@sha256:8f642e3874dd51f5c019fedb2fb9d72684e91c7f75e45556e433b4fdf7e25af6 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spicedb@sha256:d278505d2ae125d3e3e2bb5828783fbb9dcdd95279b106d2dbf370142c9de482 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spicedb@sha256:50f17ee483ceb8be4c14e639b8ff18afd135b05e995a629ba2c8a5af67424970 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spicedb@sha256:9b1ff59d22863db7c14d0f031a0ec555a3b8575e3c7bd14b69d0bc80ed61febd |