Sign inSign up
Dex

dhi.io/dex

Dex 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13

Index digest:

sha256:dac2867dac4024aa924127cc2031801c9ce663081f6144998b04db49c1f1614f

Manifest digest:

sha256:ac428f9c77226f8da654ab1931282b7067050dd0f2b6ced54ef13175b3c91def

Size

41.14 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:43df0be609fb3a8c2ebc60c2fb69a23f25bc9424c952294018c9f587bd67363e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:1d5099aa725d1321ea31394fc97d73e91607d7d0b91ca86442474725e04c567b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:25c10498a4f9ebb9f932ce77676ef14eee61e07feee9a30d96f3812b5331aa2d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:068e65647aae6e20082aa6b50466554ea316c8a33b7811402cde5d54051a0acf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:af2b17b6403ffda2b31c8cba67f0321fa64cdc72e65947f773817a4c9def794c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:8101ce93c0564bcec3ef2ecfb94915f4d407fe8df5d1c2bc66d72563d9512340
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:4fe26d12aea64b2bd7a06c0d449c0b3e4593ec0c5f1b57cba983c946afb7381a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:b24efaa8c1f19cda47f86ffd418e0141c00bab64f9f9c85aa11b8beeec89f70e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:ae57a745c13c39bdfa407afe96573428fea498829a6a9ff9c3d9e4b2f436ee4f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:0d29e8e78b9b081babd011d7e64f754f07f9535a0b42e0df3c2c4b35904bb691
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:a4ed0d9356037dc57db1bf54e83e707871c7eabe0003308d4d686e900d831e97
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:ae3b3df8932800e4e201e443bae5213c9e95985c766ce1eef75ebb0f046b6614
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:77e61ca58a52385dee659284f94bf3126aecf93c150479e0f629cf3801b1d098
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:74c7467c175634ea8c01c74c2fa111ec8c48830b52c0dd2b27648c63c709a532
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:316cb4e4d1293575357603674500fbd3b7f789f8e44a79efe65666e65d121d8e