Sign inSign up
Dex

dhi.io/dex

Dex 2.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.45-debian-fips, 2.45-debian13-fips, 2.45-fips, 2.45.1-debian-fips, 2.45.1-debian13-fips, 2.45.1-fips

Index digest:

sha256:cee90cef8ac27959151ee37308f623d0884591aed8d6c44c5694f7cdc2273aaa

Manifest digest:

sha256:562d024f17e5f4ac36f6329ab0bb92b1cd659373aa6e9bcc753943600d57e54f

Size

46.23 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:471dfe9f72fbe8615127296de8cc3ac101cd3d3c9ced621f8b65ceab4751b72d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:b8f18c0915d0de3109a38da773ab917ae4eba688b1062f69f2748f57c733c660
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/dex@sha256:a784ee56228b69a25fb016e86da46faab493aadc2dc6ef59919209a6af005023
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:59a7899f60695e74622203a6bce88e9ad2f8584ff05de79d8ae5da4fdc1b2409
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/dex@sha256:b4496fbc8b8bbc43fc02fe9e5178745b09e6764da32fc1c11708c10e450905bd
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:1238bcebeac62ab17baee2ca06e1b58050ba641fc361b7df743ef7a9ef7f25c7
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:4a233edea36dc3b5db50497b370dbe38cd57151aa8ba59cd4615bf1d6c3ad5f3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:17b2b6ee9b36e0d871c80cd839d2a166417fe3f83826f1ba6e1b2037e2e455d5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:83e1e1f07b54a6521a1a4f3827fa96cf85b7d3259799f9d2ba153b960bae4d95
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:68933105f1030f18f8ab284542d4a1a29406718b6281649815aa663f29bb9ee0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:4f1dc269bec128c885af5cd63f486acdebd2dd2481a8b293364dd494baa0e66d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:eab14b585764f266683036f467e61cfb4a7b40b861a77da4e5369cb6408502dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:76b6d6a30e40d9148c1152d32a1e7b21cb6649bb7d6f976628a49ef133207945
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:6a55b8a0368a8da767e1e02dee0b09ad5cf3246dc02ff4b600d9829c1072908e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:9a72fdcc816a7873df921bac2bd17b60489e21b407e9c4d939242e94aa72ee1d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:b7e238f9417ffe60a7a413926a61634eb2f3c3da85ba6366382574b0daa357ee
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:1b1414b1c449901935413314fcfc55385ae66df3beb40c59ecd86a0eb25c3cbb