Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.13-debian-fips-dev, 1.13-debian13-fips-dev, 1.13-fips-dev, 1.13.6-debian-fips-dev, 1.13.6-debian13-fips-dev, 1.13.6-fips-dev

Index digest:

sha256:2c49ecf5053ed3302dc3cfa1d6becf1c79c8efe28d0b740b5b6789ed2fdd53c2

Manifest digest:

sha256:d021783d43d6a717b868f8634e984c0e399106a74fe7cbca76c15e192f3ab6c6

Size

51.59 MB

Last pushed

11 hours ago

Vulnerabilities

2
9
1
1
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:215a8f339ce912fe7f5c2acf1bb7e51e4244676533fd1712b8dfbd22dab7e56b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:40500dbf2e7295a3762a38dbf12daeba869affab258c54653431759c1db65e3c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:73f8692b8d1be622fb22ce9345e3c3b2a79220dd7b4b708c73a6c912797dba1e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:c2cc6f40fb21923e93e9185139158d74e1674d1bb612cad8d8e4ec8142a87d42
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:1d45eed88b048c8247bf84639a2e4981f9816aa81b43f088876d1a4d1bced043
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:2d5dafb4954b942029bad670573a18242b4c3981ebdd8a47c800017607766e7f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:1f724ef99c748861e3eddbae1d5209a4cad9404d54ba5a8d9122427a78f85d44
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:df64f403873a1935b44bab092eb349b35522b318fdb73feb541db7dcb28bfad0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:fb1d403531b5b2bece3a52b6771611347e18b3a85073721a5a0d4512bfc2c562
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:3a06c93bd5f25eca76d2606e20b5c824efbd4a6e9f12411250a4f374ba808569
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:78024a31af2af020586b38960e6fbed9831b5349332b2b0d2ddbd43676f7fa59
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:1331551aa16425e39ac9d4276e565752910508c0c292b7a30e6a631372e1b012
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:7837fe966484d6d7a7a22e2907cc964ea0519f750be46c553dee011b772a226e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:5865537ef440bb0e043ae27cf5fd7f1914cc0a7375cf7c4efe7b9c5131de6267
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:d7ea5056d83b6fd67226d1b56832a237db24a23c15edaf2f8e0b4d4470f4d4be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:8c71283a0f3e756b2f4f850bb3099f3801d8b92196d0919a7d09d8250671bd0e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:952d6e7e190883206c6b0a4acd04836a40d2747f7155c63fcaba916f25c3b9fe