Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips-dev, 7-debian13-fips-dev, 7-fips-dev, 7.15-debian-fips-dev, 7.15-debian13-fips-dev, 7.15-fips-dev, 7.15.4-debian-fips-dev, 7.15.4-debian13-fips-dev, 7.15.4-fips-dev

Index digest:

sha256:fceb1ab08d80b5a842862668675808b1ba916b780e2095101c3e9cdb1cf6b4bd

Manifest digest:

sha256:882c19affb00c3515bdb39023423e1522acda1daa82cbc093abf89db7a173fc0

Size

41.77 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:079892d7e321edc2bd1e5ed87e66624f96f9407b675bdca45d7f185cec35f69e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:2481b7c19cf75b75a5dace92d48ad61d79e86b02a8e729a4300284c08f85ea58
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:78a2f34bd623fcb0b0a4da620e70837b7c1ec2e302490cc2b6fed3e18471f9bf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:fe08bbf8f72021e4eb7761074a92b451dad8d4c7dbf32aa3310fb0a8d3f92c49
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:8e657b88ab528190ab3f0e2d3d1c85885c0ab86bf8bc0f12e6e43cfbbc590106
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:b81e61e976e7817a9f3565f3ced812f34adaa9515ac9efbf562ead4080d74beb
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:f7dab8607c881db8f2c86cda8ea3d340fa1ae51acbf10b55f47a52ae3335805f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:c85d00b6f9c4c4e207605c63bc7ddd43e5595b3123fc3cb08dd67605e574178b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:36bc08993940bf0c924be43a68d0f96c26faca45068a0a547bc2c9947010ee7b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:05e0f6ca748f6d517c56b129e3c684aa0373b9bae176f28444ff2cc7bbd15d45
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:c2cc9b74c58d0dae919b0ae45a4889319ee13aa7056033ba7bf70815a5b377c7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:3ebb422632776a3b78065f44e10e7ffcdccb34436ec0402f4479ccb7f93e18aa
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:893d85c02a4605bbd12d8c195bc3098d80a7edd04d077042bdcf60ce8a390772
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:ddf54c36bdbfdc58e72a1aa11e7ac8714f0d9a0e7c8fbdd5f783c2eb2c40b78c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:5f0b531586c3b0e0ff5031fe2a30634f9d91f5f5eb7c700a8bd10119909e4f60
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:2a30ff78bc0e41887deade3b2ec2453a5e6e626a22948b700213e8fb00b2b361
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:a375d22c70cf240c7a4bd986e86ba233e461648d2387f0748f210d9b7e6b5cf0