Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.1-alpine-fips, 1.1-alpine3.24-fips, 1.1.8-alpine-fips, 1.1.8-alpine3.24-fips

Index digest:

sha256:b7674938fa8ef42924827cdae734429b9c53904794d597526907e1a6ceaed38e

Manifest digest:

sha256:d7d4c6699639dbb9afe9906acef35cf3888833925a60915c201128a4a6a28590

Size

17.71 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:b87579e7d3a1f76163794fefc1221ad307350d92267339726c7d486be1d8ae78
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:d68d0783cf2dab3fad656172102dc632887fec19505cb2ad902262ef4482d3ee
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/authservice@sha256:9baed7b3540a41af1bf2d8999b028aaa8c478770296ffa6173fc9c5eb5578cb5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:71ccd7f999abbb2857a14844d2bdd3df90f91fa42e1f17530d9be8b34422b800
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/authservice@sha256:1a898040dcd719389a08700c1522b25393a253a8c2b86bf5d624a4b9091aa1f5
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:ab855170c3c80a6cdb6a76d7b1bcb57914ed36761d0a80c073ef7d304a16c951
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:4f0b91a7adc3bece30528f625aa84e81ede8e532fd03bd6cdef8f8a7a739d9c9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:a9ac04192cad844da8b3e804472d5ec7bf115b384ec3c1adccd2a9c55964d3c5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:32b82b843fbabb28d69d0c79117672c65da4a865cd79250756a0ad1ff42c4d9a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:6eb196ef5357b099eeea75eebb11290a1cc476b33361b982d918019cecbc07f0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:7bc01cb3a9b91a866257c2f257336cc37978601f18249dba26b922477f2e688f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:70b74f2bcc35c9a3f7a284feb6ca54fab001723d0a336f1784f1fc9594d77a70
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:ce2d7d7fa3bbfddabcd2ec877af12361deba96da1752f11df98e9d9d5440e3e9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:3ba03423ea67e89bfc66aefafef6a0dd3361ea9249fddce81d312896884ecfe7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:fb9eccaa0b29c6ab80d164bc39fb708c0624a8a77dfcd0f1491bff87c6f5f5eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:9b46d3c11abed51e1c8f384fdca9e73e4d999150f9c75255aa21cda020db3cc3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:9a1b8f053d5936c6b1b7b368320ddf15aef801b4429b194fe6df54245724b901