Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.11, 0.11-debian, 0.11-debian13, 0.11.0, 0.11.0-debian, 0.11.0-debian13

Index digest:

sha256:67541b5b1e0351b1afb9007540c6de247baaa33251b6e280db973fbca185b7e5

Manifest digest:

sha256:9c93f793c2dc024954fb557cd5ff191a2bc9b7f55281cae8bae4cd4d5653d531

Size

6.32 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:5c5d826b77f8b7762fefe358b83547e9b5a124ae7a3d103d21680f4dd2598e9d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:eab528ff119b6d4cca5c4635f0d512f090ff75255bc2a54b928c7f7cae3cf045
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:863febf3bc9674d042cdbf3c84bce123b66cd9502a133d2b781e97e9210a0b36
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:c33192c0d14656d8fb9350f344f61a63e9d952d51631ae65a18db113b96a4854
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:1e87f8c241ab6e14af7c169a9195a3deddfc8e517aef0202f9841a4e9bb27e24
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:e8697a4259983d56eabbc901a2d5a377a0be78cfc2a3faf0dbeffbf00dbac917
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:fbe326a4f1968ff105bc806ee4fdc566c60488363e8e8e4178836a0efddd7f6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:aabf48d1b37998bbab4e16ffa948e305be1d384674fa260ac3e265bf0c5c2490
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:b4b9ad9132f4a0efe791366e60f013cb2341bdc025fef55d4b58f5d836865950
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:2135c607a2a27af535d29f69c8bf63fbb6598f51bcfcd8d53f18d8d2d7c226c5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:225b0c94d5b1c45248f4c24cd9a84a7b91ecf9311236e2cf3380aec1998e5af7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:e2616ce0db87c08fbcf2092aa098568690e833cd280b7a00fe5126c137ce4539
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:48c7e0fe9bc0bfe642bed085e845ff878a1b1fee405a436a77eaf6a3ef690336
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:e71a225485e04af09ead7facee3fed5faa35bae20d0ad4a6bb395ef7101ac810