Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.13.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.13-debian-dev, 1.13-debian13-dev, 1.13-dev, 1.13.6-debian-dev, 1.13.6-debian13-dev, 1.13.6-dev

Index digest:

sha256:4a70e85117496a236d4f1d9631bcc984f2aa07749163420e8ba6bbb5cb59cd97

Manifest digest:

sha256:c2492262fe5f2beb724f3e0d19b8e0a1441f588393f714ec7f8f347917c20ace

Size

88.49 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1.13-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1.13-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:fbeafaa47fbed9044ae0d8fbca87e4050e5dd084437273f9f3ffb8e5ebb1c0cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:71316eb7e54a2add32c93e6efaf3840e94cd126e90b9afaa278813b45fb258ad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:e924d56ff4113ee0a661835e28ea9e19d9aabc372f4812db108f94912e48d7a8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:bbe2689469e1f8275d4a0b9805043167f8de51002af6606849dd122d2cd024a2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:60d9bd2cc1a49b0bd834c39cf76310baeef69b6bb793152f32cba4589542c61d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:d34d481d70ff14a4eca1c2ec1491d6d980b179edc8d8d63b5be819b02cf6bf4a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:b3a06be2ebebb6ea7bdf43d99cf18272c8df94d58a55cf33f79f94986c6a4a09
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:f452e5ca89bad37609d54a6a7a5d3713464bc5f8dab849d09eb353d049128949
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:9fee1736c5d4ebdc8adcc5b7b24bd9c957981e9a20e6721d8a676a9d3f1e3af9
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:517b15f6e95dbde7b1907491cf883fb917022d3a973f5acee497e1e3c4662a8b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:77292a8b68f90481c8361916caa1d1342c8b7568c45649b91e73edcf3c753a29
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:6f978286656f7962230572b87537cbb3bda5d7cb7683455f674bc85a94b5fc26
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:868afce189b99a09f75e32396b060d7579ff307e80325d2a1f7281d4d1af68b4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:986f8b14f27946cf1d39ebe0a6575f1b3dad7818404391141b3cbcde24c33aef
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:a99b85fe2dc2087bf118a8896f2781edea2af28f793f19fd07b5f6f84f0dc3b4