Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.13-debian-dev, 1.13-debian13-dev, 1.13-dev, 1.13.6-debian-dev, 1.13.6-debian13-dev, 1.13.6-dev

Index digest:

sha256:5a78e453b419f343ca86550deca48be3e0a07ab66015e18b07c98708053a1d44

Manifest digest:

sha256:1c205f8a5aecff836fde6e9e37898dcc3121fb28316d09578e18edf41070bfa4

Size

88.47 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
1
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:3a6084e632509a4107b3ec3c50c0c5dd1f3eb74cb53cf61f7556e148662b5ae5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:84f30f57418d1f9bf481e9cf8191ae9d370a96d7e16e421faca623993165399c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:d8b99329cde1e5577daaa694c61ba9e2bc4ca7b30e30c4df408a5775679febb9
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:5a07be9ae458476686060238ce48aad8237d038f6cd694460ee000ccf4e6bebc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:840201caf282f8ec9544083e8d357388c15207a2680297a5a21f3cf3c8976d27
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:a70975e306ea266a9b5250cf4564df0fea8867da7a287099a30f266e47f4a257
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:f0df56bcc42236c7db76449405f74c6e1d09e904e1c1cf7b476c5ec6c4a53a2d
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:83d0bf995ca790527e417a41ff36c906cda34331712d24e92a708b73d044ecb2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:d2d53b9f41abd66218f6fb2791e151a88b7cadafaa3321845e3bbbe02685abfe
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:1b49cbdf4aa7347aecfbf50ebfd9e97175fd3d9e686d7a7ad07a34ecbc9b33ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:ae03dbb8a22be90ad1c08810c9d5f7c9eba580db3b9a5ac8ae1dff22ad4f3e8d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:70d2f8cf849cc98b2928b618a57ba8892711eaba0899e1c259f3366c601e9187
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:cee836835cd3c599b8bbeff7280c610ecd60fe08b18e689524971565b66bb109
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:c1fcf3565b86b5077a424ddb7b9be5731d07c511436e2d569cca70b1cb506755
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:68cd86420c25a678ed1d2bbd3cc95e43673f4b7f8c008a1bb92a91dbac109079