Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips-dev, 0-debian13-fips-dev, 0-fips-dev, 0.12-debian-fips-dev, 0.12-debian13-fips-dev, 0.12-fips-dev, 0.12.2-debian-fips-dev, 0.12.2-debian13-fips-dev, 0.12.2-fips-dev

Index digest:

sha256:816ea02dd5a2ba580732e578af1e35adacca9c86f3931c84613d723b7955fecb

Manifest digest:

sha256:9ec3900399cc3fee129126bd818f7e4e3a022719c85ae0ab9fa3f833cb6435b0

Size

29.62 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:1ed99276e1a7d3fed96c2f1121cd736842787958251e1e7c197b5e3e22c9a09e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:9e918615b47b713ec6cbd64de6a32b64d03be0012f8786074fc54928a53e7402
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spiffe-helper@sha256:b466d9eb8150970d2dd94ccd691b8154aebec8eb9bc7e095c749277d61553c8a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:4417e246100e7e6e1a97ba66a645606da05370162d46ae7ec95e47b183c26c85
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spiffe-helper@sha256:3291d0e58c00eba5bc528a53daff2971a719544482e2f4107800257ebd8436a3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:4e559e917d86f4e3afd56dcb075087688b559cc426b9cbb36c28c5f73548a3c9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-helper@sha256:329813aafb5730287798f7415a0499ea04d9e8fbd34d66e6ef012690f9391af9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:19568e97dbbe1688fc4258294d07ac7613e6bd3fc9e3a33fb1be3c4f130f12aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:5ad8efcd55087859e009683c2fbcd16db39a69683d68452408b2862095b5e5b0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:e0fe4fa028d834d87e7f9391f0a746a4fbe079139c66449fd21b13cd7bc70a84
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:8428bfab663981289627f85b5f5dae499e5d874b549f0dde33666b3e29bc82b3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:0d9e8cccb1f7162150643826e068101aa403dc4d505a69749b0479a0a4a5939d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:1e62f1568410ab09faa682e677ab9ecc1dda5f2ef55022ed4fb102960da8ea39
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:4831524121f240054505cf119629a373074fc95545589954bd5d5fb9f1c2013a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:3f941e9ead58eeffd36379a1da369f188eeca041a44d980f3fcdd88829caf25d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:b07f9b70466a6aab7be31b1fbdc5e9199ddd51ef203b47542b82d9521d9c0ab3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:61d5fae522727e872c20413f0c7e2e557eab4d5d758895dfe4514cb15e26d451