Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.12-debian-fips, 0.12-debian13-fips, 0.12-fips, 0.12.1-debian-fips, 0.12.1-debian13-fips, 0.12.1-fips

Index digest:

sha256:fc00bd51dd15e85ae2e68203d8e846ebd6be7f9d3b7555a3979c8b96c965ab7e

Manifest digest:

sha256:4290cffd1fae07cb3b6c356a632d5d04046d1a891053ccb83f4e8ca7496a234d

Size

14.47 MB

Last pushed

10 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:cf2bfea7e3f98b47e056057841916ff1da7571adfa20528086e9ab5aada89926
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:3118d4adfaa076d04267cadc222c9a4ebeffa941e237267d613fc05331c90c4d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spiffe-helper@sha256:b992789597c83227316e2991e369c3f3ee0752f3b49592433dbb2207dd002fce
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:23a9bda3841df9a697ee6a6fa94472ff5ecf8b5e45223c8586c18b1f50d1c8de
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spiffe-helper@sha256:68c708200941c7e250a4997e5562c25afabf7e1cf6e6890928bb424830f8df64
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:01f2fb47ee6bd72a90cc9eb3895f36864b3a5bec547974c59c38499c6317b26e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-helper@sha256:1f2855cec9614ff1c3ce605cc59f39d7f8aecdf1e94dd2a1300c3ef1db3bb668
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:cea8feaa3cd051566dd6bfc20d3b5e4fc2ed798d4365ca6515f16f875253773d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:9f517eb0387eaf7467c5d00b8481620f7fa78101e825f7047eb6235d2e583f50
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:e7bcfd75ec191be84801df0529ae68e261f6a8e8ed57d53d1604409f7a968523
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:58276a37d6edbabdf6057229a1aff09aea16c569a45503e4dd7fa6b8555c1efa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:cffacc4f007fc84c0c4ead7204f99f890eee1aa315f6d84a98a90a95f30d5dfb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:ea1b39caee5d47445c6ca3c5b38dda1aff23188dc43ecf538a375022000a1d1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:fcae1ac0a129bf5bb53696cca4025d9bebb4d14e6bfef33bb3f9d8241177c894
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:d41d6f50683794966d972f5a8921bff4814b7fbbde32b4b1cdf30d0f9db0a247
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:12d795ffff285c17047b04c3d93486b52f7da11fd677be7a543542e7651f446b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:55a381dc9db4c21a2063fe0f861c48e4ec7c1c05e984186fc711eaa3022c9162