dhi.io/spire-agent
1.14, 1.14-debian, 1.14-debian13, 1.14.7, 1.14.7-debian, 1.14.7-debian13
sha256:893a4db86fe14f299d3674b053805dc69bbb2f649305eaa342246813665353f9
Manifest digest:sha256:72b61bf9bbedf939568077e0567d3399e948fb93aab470fabfb62a8bd91d7d21
Size
14.62 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/spire-agent:1.142. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/spire-agent:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/spire-agent@sha256:782964f8be0a63001839192776384c79226ab4a222bc55e1bca44b060333efd7 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/spire-agent@sha256:f731621fc9b83a0e5df6c8e730976345bd4756789586f50c09f74096c1d1e3c4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/spire-agent@sha256:01a00860815585fdc940fcead365a20b03f29f61142c240015bdd6f085ca78cf |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/spire-agent@sha256:4fa57ccd408fd6a5be6391cadc02b41b4f6485f460a5ddec26ab5efe17d77389 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/spire-agent@sha256:9393035905c88bde87be526f947e9e9b60a524283a68d0911fa33fe38d2c5606 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/spire-agent@sha256:451ca69861400fd8c3fbdf65f5731215f6fe701b7805764f88f313f967717dad |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/spire-agent@sha256:d67e88eec43c4e1985db5af1da210a288c3e988615104d596c73fd6761156e16 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/spire-agent@sha256:b1ff189c462c4ebbeabd914ac83484998d04036dbe46204258d9e78a86496368 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/spire-agent@sha256:6c5fd9886828350197ce6ca04b0420767aa716f7ef45b6b46393bf3ef13f724c |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/spire-agent@sha256:677447ca343d83f8bbd60e3ac95f8dee960e66b991dd1e47e78bb9a076ea0505 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/spire-agent@sha256:1b111799232f32fc66b47089f245b5a186333e5a3e6243544b5b5c0a334aaa09 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/spire-agent@sha256:b46dc254b1aef98b916649c1abbd765ed0d56e01f88cc5b9fe592f3cede75174 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/spire-agent@sha256:9e231f72047943c1e84c8f88b41dfb50fba302827444b53e1a55f4b1a40e782b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/spire-agent@sha256:71cb2896e051c30b6c149786ef817ddad44ba20880a1cc4673c6c1cbb3acf838 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/spire-agent@sha256:ed82362f1b3daeccf113a87225447a32715bddacd500c09c54cd1d0a1241909b |