Sign inSign up
OAuth2 Proxy

dhi.io/oauth2-proxy

oauth2-proxy 7.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.4-debian-fips, 7.15.4-debian13-fips, 7.15.4-fips

Index digest:

sha256:c192a90ae3a4f47ad312bf499edf9c9a6b427cf6e1ceb404553744a918f80778

Manifest digest:

sha256:23bb42a86417eb8e275482992dffd35f75c959224f12714c69430e1f192ec31a

Size

17.90 MB

Last pushed

4 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/oauth2-proxy:7-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/oauth2-proxy@sha256:f10a7d05a4ae15ccb321ce5c266475210ce55c35b199c5a7cbeca2af625af599
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/oauth2-proxy@sha256:dba338865a6867b4b5f08e6288ca44314a081d5893436509d03e0ec93dd7aed6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/oauth2-proxy@sha256:a0c154ccc5b397b5e5a8438af3110b6e993ff049f336a3bc0dda8f1b5261afdd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/oauth2-proxy@sha256:6db2ea9eff74b3596eb09c0772b0120cddd7a6d485cdbfabb03d438ed8364dc1
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/oauth2-proxy@sha256:e1a689552aefcbae59cda1d73322535403c47c6bd466da34f6a39ebf1242ebd6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/oauth2-proxy@sha256:8c006c11b83fbc4beaf3875ddb28978e48ff09c8270ade887aab4e8861333239
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/oauth2-proxy@sha256:77394d28639b00fa4c2911222d53bb782122a2d82f7e120fd65977fb7b4efad5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/oauth2-proxy@sha256:391297cecec58150a1cdd72f23f878bfeec770bf734a46cf3ed3e58b65ea40e7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/oauth2-proxy@sha256:131698964fcd8279920445fb7faddd550d65c3a7ab66fd03360e2a8ac66b8450
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/oauth2-proxy@sha256:b4a225b9663642e08b7cd62f4e48e0f2561d4b0fd804542490d7cf67eb3e5ed2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/oauth2-proxy@sha256:0a7925feadbeaaa10a7f3f52cfd4944a267ac4e5a390346ff24e24c6c5f28c77
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/oauth2-proxy@sha256:fb9cd3a49c4a91ded98829f93f17e1a85ab1e0ed727b14a4be8ac57b16541c04
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/oauth2-proxy@sha256:50b899f9cc063a31ef714f0f3da2fbd81e442278e603e3dbf39701f04f1777ee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/oauth2-proxy@sha256:d4d0518fd7a08e157476e281bc53e6ccfddbbdc70b666b4001dfe88b5886ca2b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/oauth2-proxy@sha256:449ca64e376806dc9c1fdb154f5a692d6894725035037a16c15664309b6cb6d4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/oauth2-proxy@sha256:c9a62a85bc5e63251fa80acaaf021a7159d556767fab8ce81b31d4965f51348c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/oauth2-proxy@sha256:2a1b3cbce8086f153fc1458a3b57dc7ab31e2cf1c199f9ee9200fda5d8751a76