Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.13-debian-dev, 1.13-debian13-dev, 1.13-dev, 1.13.6-debian-dev, 1.13.6-debian13-dev, 1.13.6-dev

Index digest:

sha256:4a4176514573d580ea279b22ca3fe34f601d0668de3d04474fb957105d54a092

Manifest digest:

sha256:875e63d48253ff2e1e01e45ce5b2522ee0b14be2d484475fc36a3d0b8fc0f54e

Size

50.85 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:1bb831841ec77034c62b2a12a1f73fa54b3dd64f9e8cd8d54cd4c92b0fa55a94
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:44fdda72f5b9f4e1d4e570c60bf0330f34511af67b39cedabef5eea7b6348d87
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:e3ec02732f91ffc62d6b76680b44321874d5fd74f56c7edf0a900ff09584194c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:b2f60b4343a32b8e5c60ce1d693b93bca2d44f83bbf7e415328d508c983eb510
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:29f342d4e9830affab9105be30bb7423e3d03167318294e7088bde0ae5b8fc02
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:883ea1a9eb278919b52f38b3e9a4a515843f727584b0752197a2e17136cdabbc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:45aeeba3201dac7243c54e7a2d086dbf03923b553947c24009e1f265961d07c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:109328a64869f6e84be0b3e474956af9672543d5edccd329ed98d85bfed8ac33
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:fb1670234ea9f1f5b91c5b7e1c4234c0f4f422e500f7e22556f2aa9a7686855f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:612bc9aee68e393344c65dfb8cb988b7801a99cb200b2bfdeaad95c755e86427
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:8c491d375d88f364afada8d1d0d9748001e5878e76f16fa7aef22c9aa0b2516c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:db1dac2ad6b7f99ee4ff42092f969b0e4c2899b97d63d755aab6a13a976e47b4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:8acf164d13ce092550a1baaf598e4d6d132cc215d67f6b430dbfba4aba7dafdc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:9a59a3cf6755d4aa68a11a3e0c2ffa8b4f650e217b672cb2105ef9cc16c8415a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:83435f5491f6af8e12573c8196f0c5921463d69bad5d7eec87f516ef196f31f5