Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.1-alpine, 1.1-alpine3.24, 1.1.8-alpine, 1.1.8-alpine3.24

Index digest:

sha256:f7902f10fa2e33bd9411e4d232901b7d41370b71f9a9d7f565ce9137b21d01d4

Manifest digest:

sha256:2aef56bc57d054e4c1579f25c96826d78e82b9a1d2871549bcc2d0482a9635c5

Size

14.29 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:15b0a7f383dd92b896bce841fb0158eea3fd21068aef7a4dc4cd020c592b200a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:72a046365715053937e4450ce8269d5d8b990181fc787d5c524c78b71c50e91a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:6dc16ac70bf9ca730ddaceabd211752254b1b2ab36a9e02042d06e6d9fb326fc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:83dd72c83fbf61e37a15131139b0993378b97a06444c4aca6ae8631551dd825d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:9deafe6ae32bd7f4daaaaf69a8f5620706828c86c5f0d06ae1ef02385c234fc6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:41af3625056a4f19e3bd249c8530a0eebd7b640f7f07cc59888b84e07d19c52e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:6baf46a9a1f7ec4aa5b91a54d5b86b66bd45b8e8031652a769978e35d81eb3c9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:cd3fe2e152fd634bc1644f11672779be6ddbdb4a1dedba8148595259b359be80
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:d203d2808e00c8f9ff35f23cfba000cfee349e2de0f3747d88ccd363530ee870
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:7b966edf6798035bf444521b1ecfaf456755e0a8587042b9772bdfaf6c5c2838
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:7ab6e74c2d65340f42c1c313d683d35fcd3a7a49f7e1111237e5ab9337b1527a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:94ae92de9e1929c4c8aca663924d28dba693c4a45f74e7eb8a82cfc122a9be6a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:4c9d25446332b5240bc931fb4f3377f1e69f943d5ea814a290031c49d4479821
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:342548a4726ae6f66dafbf1726e325170567faa9aa5224d0c075da24df128bcf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:11f2a6a6a1b33f1ee2795482d8a273adc11a28388c9c13a2ac07304ec746ceb2