Sign inSign up
OpenFGA

dhi.io/openfga

openfga 1.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.21, 1.21-debian, 1.21-debian13, 1.21.0, 1.21.0-debian, 1.21.0-debian13

Index digest:

sha256:c0e63c965714625f0efe8390a9bc3de5f91cb5b95cc19ae1012fb551e2e69ac0

Manifest digest:

sha256:80fb52d6a6a7cb1f38c01c38240f768ff1af1f08cd13c7c8883011258ee56808

Size

23.17 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openfga:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openfga:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openfga@sha256:0da413aa926737c84f1764382db2fb8691b2dbe2d13988645137e70f17c59134
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openfga@sha256:e2b551469eb78813d6fb6341ff20cb183d37ac222f24ee647fdd01d30f7a1a19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openfga@sha256:a801f5d3e01381d0ef1d94be02d4dba80eb52156b66152078bb6564e05de2130
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openfga@sha256:4853f0db66cbf7c3a3d06706da3dd9e77056e53458ed1445eb3cfd9cfdf21fe6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openfga@sha256:cce0581bbeeb0e449f6ec98d4d348f37f93ccf903243ca6fffe7a1fcfdb2d763
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openfga@sha256:618b4e8f23d0c3001308072fd4b1daf5b5a5c4f187b1feb9c78f1f8bec867b0e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openfga@sha256:369f5fb339d34e95cb5e47bfe0e98ad6e6ed22ed4531da60ae34ddf63117e993
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openfga@sha256:6b371d962b570a474c3977b40075410b231e4a98a96271d27794c6c1310f1c70
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openfga@sha256:f7e3610d1517eb35070f9e05763ff626d5272c1087cdd5f9f6579bc886d2a7c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openfga@sha256:b239b651aa85092350aec097313eb3e242a9ee76e45fac9cc71a1850c411734b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openfga@sha256:caceb4821dd558d4757e713cc4c0a13f6cf2739d39c73765cf8fb60d5b52a27d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openfga@sha256:5968389c0b47321c13aee2498315d7d4bdd8ff127c7e2902c1c0674d95f527bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openfga@sha256:937c21ed98449ad3c5f068994f2c4fa599d84d37ae9323f5964d1dd328251c0d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openfga@sha256:ee76b80d6b7e4fbeb2bb661f818b4341581b627e7892d8712a14a953f2148a21