Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.7, 1.14.7-debian, 1.14.7-debian13

Index digest:

sha256:3a5e85405137f4b8fc7ba73024e303ac709226554d3776721126e19480339c58

Manifest digest:

sha256:894e160e54f47de9ecdc2d3df4fc925c5e7d7858f1ccf2e0bc9e7e5a8f5fa0fd

Size

14.58 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:1b2a8d731b982098cf6d2be8bf20d53bc5d86ed5e12fe9e7991ff1cda48ab573
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:14413e238c55d7527b87c4c3bf4e2700af1276843e9a742415bec04c74310cda
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:1f450c8c107f1e53719440a13da7b6af2fcc6b82532e773605e09279eff38024
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:0abd19c12580b5dcc97f89fa088d0169d0f6feb22f2c8bc6c1fb9c95607494fe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:1d85aa4468734fdc8d4997d5beb48fefe49bf5c6744300f8edfdc4caf33ce592
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:cb7e64d159ec4e62ec563c374575d6b051fef0090f104521953b4c3bccf9c732
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:8c7991e296fc33cfbc3c8595053297e4d71ed7d6fab7078290cf8ddc85f14914
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:7eeeb2125ffaa19c51cf7f0204a766ee90c3eb91dfc12ee06c3d12166e2d44db
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:233fdd1fcba163c685b37bc91d4280150dc68e7785bd97301cc5f85c6a938643
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:134b1e9226f3dae71f1afd70d64c799d59fa8083c5f0cd79066a385d2c0612e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:cbe9ffaa85fa84001489b39d643eec42006857e2145929f5309f3e3360662448
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:4f90b18752b2350f8cd624b7cd9547defb6d960d7d7491d05362c3ba74084525
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:e5fbcadaa051903cc41c28ef2c08f264c7bd0f26e91330518c7c1a7d700e07fb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:89b09dd004c76ea64c594051080e6f33364dfbeba2b171c26b279681cf93f84e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:b12d9f03101a33bc2d9700300af48e43663940810eb670c7762779bee9423ec0