Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.12-debian-dev, 0.12-debian13-dev, 0.12-dev, 0.12.1-debian-dev, 0.12.1-debian13-dev, 0.12.1-dev

Index digest:

sha256:b5d25a6c5a463ac04687c0cb82185cbd5fdb2566aea583a580229b60018af5aa

Manifest digest:

sha256:6866570dbd1a13241c3c442c332dbb343c401a6bd1bf034e1498665f8f9e708d

Size

28.89 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:29c9184b6c7d2f3643a6603aaa05d60634065bfd8602056484401ef7cde8a442
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:bff51d4c9023c62dce7dc4c74609d40ea9879f79caefc31c6e62a28b5be5e986
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:28834df4c897d1aa80f5da2b3bf28d78617fcf5254b84454bef536bff42b90ec
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:4cf5592b31ee35a24f3a7dcaa71fa9d3a4af6695392f4fbcc9c2259661519447
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-helper@sha256:30c4ad4ade83aaa46b14b2c01c41b68d0acdc9ce5560e7cbf381d04d4c4850b1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:bf10d9963a8c74c21ee1608003f52fcdc4d9d1230e7b247a11db02cb59b57d33
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:45b4d6f2afd74886eb29a9189c9dffcfb0a7759654404745f396c939e0bb69b4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:3cd9e026ecef51838fd0a5fc1f027a9abafa9a99536640a6de3835cb6d70258d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:97ee7da687b3ffec3f6186d88b54f3438ab040a21e5dbcdcc441e0c840b892b0
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:89e0a251d96ffd8ca1430e0377cadde875f1e6287cc21c2a0478031fcfe3a265
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:958fbb305d02c04f057743f4b65309e5ea0ed312b4aeb87eb5c43823b290da63
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:79a57166fea110f5f8dd2ed637012e1024828958724ee17820b1aa5ed5feaf43
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:4ae50f5597187b936073d39494df15ec1d2dec599fe60fc207884e90d53ae279
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:39d299a4d9a5e0d47508315f3115130cbb976df3205939b33c962711c707afdf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:0cb6b7dcf31ae0f13884d0c8163b778525f8477852350c3a897fce26d1838040