Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.14-debian-dev, 1.14-debian13-dev, 1.14-dev, 1.14.7-debian-dev, 1.14.7-debian13-dev, 1.14.7-dev

Index digest:

sha256:06c26ca23a4f44da222893efd622da74d715ebd595fd48187ad7cfeaf7c68b78

Manifest digest:

sha256:3fcae9ee81d0684c4b5cbbf709dabcef93c64e595610b87ea2b23fc75b27a45c

Size

50.28 MB

Last pushed

12 hours ago

Vulnerabilities

0
1
1
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:2735d0ad57f4cd3d593384941945e6e55436dce9ab6b188e0c39b8b0d5d63149
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:61e98b8b17d3c800d1d6a99b0f7f9e969c7b72f481a57d9d71b9f7d9810de2e9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:f234e75a0ed74e6b63a02d4e02848008b41e8c302d7f7f2784855ce5fe87bbc6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:6366d0b98f263168bf08cfd72c2446731e4f41e8e27112125a1957887698f309
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:76c1334428456d5941254ecfa95b97dba37ca2892b732a844f7a3b3444ae7d69
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:620c6928fa4bf1d54abcb243b6d93ceed7cda2b9449ce633809580dd96a5b418
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:4deb3252638f1d945debc6d4a2fefb1d70563fcafce592bc6c5d3a85f625246a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:09c11120c6149c4aed25a11888aba96f70282d17f51a9896ae1d41564971356d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:81c50acf0637d2fdf07b84cc328973dbb6af687783033f6b450a3eaa59ced6c5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:7b166200dc0fc80d00be0a2db39931716d23237a537bd87a4397de4dd462c0a7
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:d949d1ae43740ed162e59b1539bd144c6685f6fbaf0124ca45bb5072462bb6ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:92ede965d380db1a4ed5cc18ef999830d2b4d349fcb0856062098095561195d9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:2b3ecd6e184a09cf1f1996fd240f4ac04faea2854b71a4c122252f7eff471a6a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:7958df9a3ad1ae239a65c11fcaafacb9767689cb30d59f5716596ec04657289e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:e27305209a3ac1944e4193362b88f9652c48b489db330b0062fc46f757aeea2e