Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.7, 1.14.7-debian, 1.14.7-debian13

Index digest:

sha256:190766e710454dbb1ed3416ccaf8db4f9da41016f9037cf9bfec488c5adb8a5f

Manifest digest:

sha256:b8d0fee9c4156bbe64e26e79e72648ac59dffd216a22465edea290018d145a36

Size

38.14 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:117b86e79a829ebd39b6b6413e1c50bc0b01e9fa3900a7e17d9a3445503dc6ce
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:fc988475cb548c75ed43e470a03e4d958b286b07317ea23962de9c9ceb593e8d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:329909e4ec587ac65e91262908e410160dae0bd90bb48757e802adef7b4039ce
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:bbb755834a978d91935579e535d3f7fa91da7bd8ef8a26938e6ed03333369cbd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:3a8bb4d49541054b53a1591c6049d303e50e742568bc7c38d9d0bc70a1341123
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:afb60d0d90b1c578ae7001d4679697fe45a6f77b91bc280207678158f5eccfca
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:dcd4940000c0dc3aaa033f378124ab46cbbc4dad5ff6a199506fe6785581aad6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:095426170ba71d4df3ea13c9aa86e5d8876b64c6118dad59c634257dbb05e07a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:613c2cc5d6da1f7724ea50e78f743415a4de2a710b52a5a8a8ac72175f496ef6
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:37f0f7531f5836ffe226111ea6c6f14591aa15921d65e85e26962ad45950604d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:072f27b55cea3067351904b9e730f7367572797115286398044adc3d98890016
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:8e319a6873c4abcd55ecf7feb57677bf23bf42b4803e309b7a50c39a2ae782e7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:48c8dc3b057debdff322e29ccef258b958d85b5f9c79a5a5bde2bd2085093433
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:f92bac521355f4964c13ac881edd463bec2e73211a43959873ae5f0ef0350849
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:3a143dca08394caaefd289601b762fe527031782992b8fb36d94e89a9de30787