Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.14-debian-dev, 1.14-debian13-dev, 1.14-dev, 1.14.7-debian-dev, 1.14.7-debian13-dev, 1.14.7-dev

Index digest:

sha256:1fe029df83def22509d3465bf3cf2c65c98bf0cb431f193a6b604c19de4b3928

Manifest digest:

sha256:e0a573a80d7b21e7bd142b43829e97f1a3f99f88356345447f24444f65e55568

Size

50.28 MB

Last pushed

18 hours ago

Vulnerabilities

0
1
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:a6d2b1f105240259d65be1212666e0d6c0be611ee8d555b02e208db4fb1e0452
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:04353223de96002d960d520480f3b8b3ac819dbf38841a775aff4d4bf724e959
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:8558f068859e8e484d478b0b8c0e4e511062cba7fd25ac94692ef7e4a33e5b8f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:94e78b1e0b666a49bdb934eb9fff269a1492e8f56f623c2b02e7308c6a9e1389
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:f4ce60f618685ad481b4cfa4a42e925619202b93b5e22b017053d1c02c8fe6eb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:7ea465391215d25db76fa0ebb0b2b0ac277119bebece884f800bcc6448c3a4b2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:b18d7b628ffe9549bdf092d3e9632cc72398d9be115cb9fc9a9f1af981e0962f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:0ab53ec0d749df5d712e9d488119c5a7b8e450cee162f4d1ae85f81d15258d65
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:c6a8cc074f903b1420211c491704870e7c81f00489a4717a42aa29a592e6fa18
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:a9afb55214ea5c95275a9f3d862fcdf7498a6f3d22f75f8c7e80fcfc5c2c81d2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:916a8c6c0ee9f3463c715ce2fc665778abcf1e06c2370896f7b1372b1a76d028
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:4c13643c8a5a58595c7e27aa0e2e1a673ffd33ca25c1669e7c2ee90310e43ce2
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:1b1a526816a9645e480a320120fd5e3f65c9bbb7f9fcc75f4c063539045aecd8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:b4950aeb4612e27173c4df6b7a045b046485dd5f0f370102e48ecb7e9c82cdbf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:a6a37fca68b83eb0bca6e98cbfde68130abacbd71f8836d5afa0f8a6331e0d1b