dhi.io/oauth2-proxy
7-debian-fips, 7-debian13-fips, 7-fips, 7.15-debian-fips, 7.15-debian13-fips, 7.15-fips, 7.15.4-debian-fips, 7.15.4-debian13-fips, 7.15.4-fips
sha256:c192a90ae3a4f47ad312bf499edf9c9a6b427cf6e1ceb404553744a918f80778
Manifest digest:sha256:23bb42a86417eb8e275482992dffd35f75c959224f12714c69430e1f192ec31a
Size
17.90 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/oauth2-proxy:7-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/oauth2-proxy:7-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/oauth2-proxy@sha256:f10a7d05a4ae15ccb321ce5c266475210ce55c35b199c5a7cbeca2af625af599 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/oauth2-proxy@sha256:dba338865a6867b4b5f08e6288ca44314a081d5893436509d03e0ec93dd7aed6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/oauth2-proxy@sha256:a0c154ccc5b397b5e5a8438af3110b6e993ff049f336a3bc0dda8f1b5261afdd |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/oauth2-proxy@sha256:6db2ea9eff74b3596eb09c0772b0120cddd7a6d485cdbfabb03d438ed8364dc1 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/oauth2-proxy@sha256:e1a689552aefcbae59cda1d73322535403c47c6bd466da34f6a39ebf1242ebd6 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/oauth2-proxy@sha256:8c006c11b83fbc4beaf3875ddb28978e48ff09c8270ade887aab4e8861333239 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/oauth2-proxy@sha256:77394d28639b00fa4c2911222d53bb782122a2d82f7e120fd65977fb7b4efad5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/oauth2-proxy@sha256:391297cecec58150a1cdd72f23f878bfeec770bf734a46cf3ed3e58b65ea40e7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/oauth2-proxy@sha256:131698964fcd8279920445fb7faddd550d65c3a7ab66fd03360e2a8ac66b8450 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/oauth2-proxy@sha256:b4a225b9663642e08b7cd62f4e48e0f2561d4b0fd804542490d7cf67eb3e5ed2 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/oauth2-proxy@sha256:0a7925feadbeaaa10a7f3f52cfd4944a267ac4e5a390346ff24e24c6c5f28c77 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/oauth2-proxy@sha256:fb9cd3a49c4a91ded98829f93f17e1a85ab1e0ed727b14a4be8ac57b16541c04 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/oauth2-proxy@sha256:50b899f9cc063a31ef714f0f3da2fbd81e442278e603e3dbf39701f04f1777ee |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/oauth2-proxy@sha256:d4d0518fd7a08e157476e281bc53e6ccfddbbdc70b666b4001dfe88b5886ca2b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/oauth2-proxy@sha256:449ca64e376806dc9c1fdb154f5a692d6894725035037a16c15664309b6cb6d4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/oauth2-proxy@sha256:c9a62a85bc5e63251fa80acaaf021a7159d556767fab8ce81b31d4965f51348c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/oauth2-proxy@sha256:2a1b3cbce8086f153fc1458a3b57dc7ab31e2cf1c199f9ee9200fda5d8751a76 |