dhi.io/authservice
1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.1-alpine-fips-dev, 1.1-alpine3.24-fips-dev, 1.1.8-alpine-fips-dev, 1.1.8-alpine3.24-fips-dev
sha256:98abc4c4e2f1157d159c908640f5a8adcae68d5fd0be4175fc9d1794c8779351
Manifest digest:sha256:da980773ac26b5b7cbe0fc3d701c445011afd76f46768dda0cadf0afafb7108e
Size
32.80 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:681bee5a9693f5e0bb35af560e4c8c9f468ac46c6ad8d5854a5cb4303b244f00 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:fc4dc26d179ceee6519078c6cd4923726f012ea85bd2e96a0bb083d0f0ed9385 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/authservice@sha256:544bdd4a5af76b76df55982120e826a3d0eeaa291ee7f03b43ed914e0d677330 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:064113b70fd063c0e3919ecdcbc7fb87c3a195512524ec1e6a5b1812e4df4410 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/authservice@sha256:b7dc808c77b869ca717fb5cca681de7b87ccc6d69ce7461b34918624d1092413 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:fe98cde65ffae43d158e3cc0eb6580defb2c8efefc2f2f52d3e3195d6f05c1d1 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:e6e3b7805de278f4d090bd0514122205f6c120956f6890498ce03f1e75e5765a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:e6c2d3f786636f768ada2a7ae06427f5a1777240511b78bf2c84121ecd50394c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:a4d2195d7fc74939162d1eca455d1a9c711ead5d18e80a4408445b1020953107 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:21afb69f6f46026bd267584baf431b260749a5990b6e155e99da488daf3bc794 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:7891e0d8713ba061a273ecf1ea8afa246a89a86993705f630adbe7e5cf3458b2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:7e1ddbe6bd6b1024bcfbb46d718bad7578300eba71faed98333b9816638f4310 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:58a41983214bafba0f3305d1cac74a32257fb213cc783a4cd7c4e671cb01138c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:ec3a916ba9bf2d4531806fd9de818a22c864fd24e1cb17231e0a0df3a2984bd5 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:bcaeb111683cd98cd213ac03e14641b6e31bc5345c0c401380739c34fe5d2476 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:d9a872a2404cf0297e3d7d5ee3f8aa429ff872ec1ccc31de9888a6eecf75021c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:ee9fdb20b694523bb5d0fe8f438d3beece92d7fd24a282c5e2db0bdbda6268f1 |