Sign inSign up
SPIFFE Helper

dhi.io/spiffe-helper

SPIFFE Helper 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.11-debian-dev, 0.11-debian13-dev, 0.11-dev, 0.11.0-debian-dev, 0.11.0-debian13-dev, 0.11.0-dev

Index digest:

sha256:eb19c8ced963a4ea196057088e5c0a3468a7f47ded9bac60941e3813643e6027

Manifest digest:

sha256:66a5470e718cd890a774a61b36e8321c2c171729f542a169b2f4f3678a3c095d

Size

28.86 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spiffe-helper:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spiffe-helper:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spiffe-helper@sha256:3bc7149f8ddd0bfdfe9f6100ea1dbdba344fe80677e87f4891818160c5bffcb5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spiffe-helper@sha256:eedafcf365e504b9f12a100bd91ef9d424a62ca82f02917eca9fb11496fd7438
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spiffe-helper@sha256:2cc63b0c983757e06fe7d5b85798245a897ceeb0784dd7fa343ecc6bc610979c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spiffe-helper@sha256:b8579308ff112d4588c85f3644f20e8628848f1a75ce5798e97df0c41690b3a9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spiffe-helper@sha256:c095d3d0b7a01c92fd7095bae43880e120c3eef024527cce7f5cd0b7d7c8e546
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spiffe-helper@sha256:08ffdcc30e49b3bfc6758115091cca68a95772d8238c60e2b8e4e772ff920493
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spiffe-helper@sha256:7cae30487d259b4ad4f58689b4a74ad0db3f968a31f4fce223e07a82a2028150
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spiffe-helper@sha256:b1b06aa8a5b0c173472a7425a47b0d5d009cd62f100ef6f06cbafb792b176bcb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spiffe-helper@sha256:f5fbf4f5049d070d5c1879133d49840c00a0e5de9aa627c908db0224cf12f9ef
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spiffe-helper@sha256:89893b9f4dd244d921f3a8043261e3379fb7f73b81a2c66d391b50358e9e2229
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spiffe-helper@sha256:8259aeadc81f59a3dda027c84a2538ddf8a0ce6314d762079e8e0f17f7e66e27
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spiffe-helper@sha256:81b98a36d18cff036d8f6148be69d20e20a57bf4c190f45ebe1e4b1d886d42ac
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spiffe-helper@sha256:1a75a3bb3a6333863458332b664a4a8533f5620fb03bfcb4f28ff625b1c410a6
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spiffe-helper@sha256:34e338fb6fa6379ed404389b4b44b9acc0f6a7b60af884902a1e452de4dae76c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spiffe-helper@sha256:ba2c6311c772d8d000f6904bfc1b2bcff1d00ca22b4baa48a24c9d3a355c75fe