Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.13-debian-fips, 1.13-debian13-fips, 1.13-fips, 1.13.6-debian-fips, 1.13.6-debian13-fips, 1.13.6-fips

Index digest:

sha256:9ecf625442c5a2e1bf05dcf0cc3ae35b0bca10c407356c8129315f692191dfd3

Manifest digest:

sha256:9cb366ac2da98b01571c3edefbd913ffed8e725a54e6952a5c091a03dfddf95b

Size

23.10 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:ab27fef2a1bbce1d17803f3f2f0cd5243dec0121bd5a36bda6812260fe9d5f35
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:d43a701af5bfbe06a6df0b25ce72931d834e9e57c8c235524f0937828222bd1d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:e85267e4ddcfc90ecffb5870993f6b328dec0ae6e93fb574777477d27e717d76
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:c05fc9e2c5ae443b5a019c262f67965ee047cc1d594d0e1b8e00d7bc51607ea0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:712723cf57b935ae0d3a6fb89250e409704ffff7a3adfae5378f6801385fb16e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:cbd3c35077fbb21ddabff5c1c79dfba0ccf368e348f4c8aef70af8373dfc3bb9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:a6d9664f4a8d4ddd89d6ff34a246e86796b78f7fcd3143c2b96a78b51ca6f42d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:f8d455a02e0d0f1bba428aa73afd6a679036fe8c2bcd72fe906c30fb0c9f17d3
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:2a5e7826a9c33471bca395cb0386214101e9993f2a72f5e8a051feeea0c6cad3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:04f3ff28fdf169d0515f1bb27792212f5c02fa72fe9705ca8ae84f8f231d585a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:1cd64a1e9e7642106c8bf40ae3045fb5e79bc7105fbd50a9a15cc36ba955275e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:b0f1a54d76e8089015d2486efaa19cba9494757100dd5b310835e4b354543fc9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:92722fb354d910514c9747f9743d749223ec2a2a797b26307fa3cbee40970cc2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:3c50c8224f992c8c64a5d5072c5dcfa563fbfc9552340172b3e05a7535a31130
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:452d9772e0b5fbba673b07001519958a07334dba553ac3109a84a4c34cd014c2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:f2a528ef43247ec48dc0f8554a8663dd9bcfcd30b7c3d6365c14dda47da62327
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:d73b5d40f037c419b5164f35297d70b0150971922decfb3ea51dae0c850cffdf