dhi.io/openfga
1, 1-debian, 1-debian13, 1.21, 1.21-debian, 1.21-debian13, 1.21.0, 1.21.0-debian, 1.21.0-debian13
sha256:c0e63c965714625f0efe8390a9bc3de5f91cb5b95cc19ae1012fb551e2e69ac0
Manifest digest:sha256:80fb52d6a6a7cb1f38c01c38240f768ff1af1f08cd13c7c8883011258ee56808
Size
23.17 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/openfga:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/openfga:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/openfga@sha256:0da413aa926737c84f1764382db2fb8691b2dbe2d13988645137e70f17c59134 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/openfga@sha256:e2b551469eb78813d6fb6341ff20cb183d37ac222f24ee647fdd01d30f7a1a19 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/openfga@sha256:a801f5d3e01381d0ef1d94be02d4dba80eb52156b66152078bb6564e05de2130 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/openfga@sha256:4853f0db66cbf7c3a3d06706da3dd9e77056e53458ed1445eb3cfd9cfdf21fe6 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/openfga@sha256:cce0581bbeeb0e449f6ec98d4d348f37f93ccf903243ca6fffe7a1fcfdb2d763 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/openfga@sha256:618b4e8f23d0c3001308072fd4b1daf5b5a5c4f187b1feb9c78f1f8bec867b0e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/openfga@sha256:369f5fb339d34e95cb5e47bfe0e98ad6e6ed22ed4531da60ae34ddf63117e993 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/openfga@sha256:6b371d962b570a474c3977b40075410b231e4a98a96271d27794c6c1310f1c70 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/openfga@sha256:f7e3610d1517eb35070f9e05763ff626d5272c1087cdd5f9f6579bc886d2a7c2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/openfga@sha256:b239b651aa85092350aec097313eb3e242a9ee76e45fac9cc71a1850c411734b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/openfga@sha256:caceb4821dd558d4757e713cc4c0a13f6cf2739d39c73765cf8fb60d5b52a27d |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/openfga@sha256:5968389c0b47321c13aee2498315d7d4bdd8ff127c7e2902c1c0674d95f527bd |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/openfga@sha256:937c21ed98449ad3c5f068994f2c4fa599d84d37ae9323f5964d1dd328251c0d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/openfga@sha256:ee76b80d6b7e4fbeb2bb661f818b4341581b627e7892d8712a14a953f2148a21 |