Sign inSign up
Ory Oathkeeper

dhi.io/oathkeeper

Ory Oathkeeper 26.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.2-debian-fips-dev, 26.2-debian13-fips-dev, 26.2-fips-dev, 26.2.0-debian-fips-dev, 26.2.0-debian13-fips-dev, 26.2.0-fips-dev

Index digest:

sha256:0217c30996852b38699f439c4dbe8ba671100978f879df26a52f8a203308ca46

Manifest digest:

sha256:7468d4c3f22e458bd8d8b94fdc3230fe7083f41d63478f3a0e5873d89a01ab63

Size

54.75 MB

Last pushed

19 hours ago

Vulnerabilities

0
1
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oathkeeper:26-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oathkeeper:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oathkeeper@sha256:2f7e9094704f3d325f601624fcbedfaa4c3acc4ffe94d879fe8a0a55c87b9b91
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oathkeeper@sha256:8e5746ebc553bde00d9b8cebcdba381a3d122f7610c8cd9277fe7bcfb9c1bb4d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oathkeeper@sha256:31b3be23b80b3e1780982839d4ea9c2f9e1ed79cbc16b7d13e0ec402950f03d9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oathkeeper@sha256:746bade12eb9a6a7ae294558cd025cf81847709cea85c81e5436ee0e196da1dc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oathkeeper@sha256:cb9a6bd0b6a3ce553016a1c434252c67efeb7017e5c6e57eb772fbeaee2f8a66
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oathkeeper@sha256:1f8a44078e7ae396265d989efa0c44f5edafe4c5f8b740cb39b9123f064d4e03
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oathkeeper@sha256:f9fa6128ba5030d43c28381ac9a2a5992a4cf146b2ba4fbfc4f7188bdcd58f41
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oathkeeper@sha256:456345c8721e07987c44846c91fead5a93556254601756f992f7faed6ca3e8a0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oathkeeper@sha256:99668c9cb4c68045dd14a8b833137fb5e4c77ab5e3d0e4a4a88e17eb48498208
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oathkeeper@sha256:5e1fc235d1385466ee472fa31a5728f2e606f9822833a91559ecdd8c7a27d22b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oathkeeper@sha256:8e703f7857b9d0a6fe0648f0e654c5242ccf9a5fb8eecd2b690aaecadb69189b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oathkeeper@sha256:e61472d6b239f3c6409c8203f47d2d408fd1a9331cbaac1a07b8c79aced2d374
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oathkeeper@sha256:1ba6187a06d609cef56600e38542ccacb8ed3d5ab6cb23ae8c21daecca0a7484
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oathkeeper@sha256:c60ca4899a4dd69e6a0138ed81af9db42bfd40c691185eb9538073c312422094
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oathkeeper@sha256:8a5773779c014d9a7d902e82f1ea71b6e97f3015a9d3f614b3107090861b23eb
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oathkeeper@sha256:92f46f676afd5572ba766b36de313f6e17593d0cdcea2460a34c9d858456ea81
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oathkeeper@sha256:5ed689d8fe7ed87bf4adfec0fc0e06964cdf3ec487c4d2ed6d8b4bcc2ec9345e