Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.12, 0.12-debian, 0.12-debian13, 0.12.2, 0.12.2-debian, 0.12.2-debian13

Index digest:

sha256:cda661407fbb81d23193b1ebf38ce1b5d8f022fefccc349d10709b0964610b4e

Manifest digest:

sha256:7e4d59042cfd03b4b51e36d2e47158bcec017fc9b700920d17a7d13cde5734a8

Size

6.33 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:4f00fcba8f1d3a6bc94174064d253eb414dccfd7eae9e0f52f16f7e2efbcd5a1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:7354533b1fa710cf75967e2c16987d65e49222faf8e3bcc41f887450d10b9868
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:1fad8c5cba33e1add20d1e06f6991f004cbc0604a60d9e875c522e9f9da8c654
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:ad5e4058342f2d06f3091bc036fe5850b1aa7dc410eaec331f01fa9e71f1a88f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:0ba1cb70e7ac8a9dd203c427deb240756e2a765aa314d86d69598edafeb9a349
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:ef9548bbaf5fc10463dc199f2ab04464b116fe5fbb1f5b12c6b8f5ae657ed0bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:5b87e911771586b95273bf314b1dbf76ca2d7c2d8e1ae481a5fa6931c3ba808e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:a35362c496cfb066bc7c7eb403d34a8c5f91f76b88d7e019b548ed8193b11610
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:a8063a16d6d7d86300b8b4accfbf6eca4e3d070c238d29c3b8fb383cf44cd866
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:680859f6c85d2f0bc98f83012ce59ca94f2bd82a194e7268a7dafcc58d3a0bd6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:076827e1e87661e092c23d46e3692055ccc99f9807335f1c88a6b134f6feb224
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:b73800de2b99a2b15252c6455a4147dcffa023ebd13bf083eb5a03c83b99a68f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:fc433c9465c1a68f0bd5601bc336ddda9446258ce03e549f699ba0bc799d0580
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:5b8dd46a6bf21030fbdb4bbe078738b35512d82b91423c2c5963333ac13adee1