Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.7, 1.14.7-debian, 1.14.7-debian13

Index digest:

sha256:a0454c3e27595688f5baf4d3741db504563590a06152bb6134002172a234a91c

Manifest digest:

sha256:1964e4a62bfcd7d5923a43e5dcf06f813f0219a59bd0a4e190b6eb7324f13aef

Size

14.57 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
1
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:52479504fe36f5ba8f1ce36717c535f2571c858d7ade4a0b2e74fee195b9dd55
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:5fd9d6e368d1b1211621beb8bdce945d6e02242eb6ec264c9eb5fbf28cab9717
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:291ccd24317ee9edd1d4459dfa19344df9bbcee5dd2b0858508975a8fbed8fff
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:3699d359a383368ae611a07df6ddf3e6402be247ee547f201528b04ad2ac28ec
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:abe60c640194cb91afe467b669f98d92010d00dce0f18f9a9b05d97d27c9c59b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:3991cfbf55e486fef502fb39c4ace2154db75bd51dc425eba9f41b9dec0ecd84
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:60192d89e70cf40f05ef5fdfb83309a7d3cbb89eea90a0c5f6cb0ebef27b5a2c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:fb39fba92113c4cd643ca55c52dcd57fb913014dcd3824409cc7b47548d40194
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:e94fd3088994bd0f64b8ddac37712a7e62b1f3445d9b8b606cf2aa9f2232d2d5
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:d705b0e1dfd6f3a368627d28eb9ccc73263463955f950f94040c19b48fcbe4e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:05f9f0af45f97122c419f5c5b609e4d9e9799f5bc8df918bb1facd511eb3016b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:4eea7ac57ad339643f42d179f588043aade45f88633d3f34eb72bfde8de7bc84
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:9e6fea4c46aef48ca0ab80020ed11e6671738d2d17f22c0dccf5303e1de85c9c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:41b5fb297255f3cd70861372880935e96f8df92b5648b2f086727b69ae247176
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:63d63ddc73b400d39d9542c9718226e51d532aefb81a751c8059205db81e4f79