Sign inSign up
SpiceDB Operator

dhi.io/spicedb-operator

SpiceDB Operator 1.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.27-debian-fips, 1.27-debian13-fips, 1.27-fips, 1.27.0-debian-fips, 1.27.0-debian13-fips, 1.27.0-fips

Index digest:

sha256:749b3a3acf96798a647c375113e206cc76ad05c91474129781d41fb34632461c

Manifest digest:

sha256:2eef791d2a0e4542bf49dcc6b46beb2e4cd7e8951fcb4d2d59c46722f7485d5e

Size

26.15 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spicedb-operator:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spicedb-operator:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spicedb-operator@sha256:23d073a2f5b5b6b281ac639fdd6b471a3b7ba06e6ee9101842f62f36989625de
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spicedb-operator@sha256:5980ef2af5bcc1438c1cf767652436fa4a64236a27e5a2812cc14cea43644a8d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spicedb-operator@sha256:2b4a86e3112666d30c4fc36862ef233c821c3346a0bb61f930a8ba0ca6d67a19
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spicedb-operator@sha256:4f6d76a39d8e2d00b065c18a7c1b3896b4cc17ce6c80bd848b20e890d9bf178d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spicedb-operator@sha256:4c6599ceda22d6780d491b1a945834995d41b1eb47bdbc1ded6bd63f43492f62
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spicedb-operator@sha256:6fa37882a6625916e62bb4908233a51f55e27c65e073caf7278f979c42a0d1f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spicedb-operator@sha256:396db6df5d4702ad8942e50cfd909940aa1c05359de0e6ddecce6d8faa873caf
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spicedb-operator@sha256:b0d03cb2094131236e77343a79838ec922efcea377aa644786b8383063a539dc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spicedb-operator@sha256:6518a1b8ef093c9b58625d2c577eb30863d45e53a297cc3fe05a67a6e14e3947
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spicedb-operator@sha256:b19a8802c1244200be3a9b87289211a121e816f4654c80c6dbab1740f3040655
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spicedb-operator@sha256:286874fa4b22ec1df01e0f2592278e4aa640a2a5254f267226029694eefc63d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spicedb-operator@sha256:238da61a070a3247051291fd78e18a0cf5f5f4e82d90bbbb1a4eff312e47baf3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spicedb-operator@sha256:85a60e238a5d74b8d01ab1fb498a65d8de0132c9e19250883d7964cf046574ae
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spicedb-operator@sha256:1c9eb55913cc616369937c8ab4c6e10ca45dd61aff5bafdc2143ebbb395b147a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spicedb-operator@sha256:80a6dc9d49ca8e1731b5597765ab6d583beb199f51b073d45a11eae31328456a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spicedb-operator@sha256:bf6f760bb7b7990c8043efff5ce7b9d523d7ee3710a22e14618ef99ee54f9b43
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spicedb-operator@sha256:fe1d2e3ca9fe88281fbdec67a07251b018a47562139729cbf2bb7152d73c9e30