Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.14.x

CIS
linux/amd64
debian 13
Tags:

1.14, 1.14-debian, 1.14-debian13, 1.14.7, 1.14.7-debian, 1.14.7-debian13

Index digest:

sha256:893a4db86fe14f299d3674b053805dc69bbb2f649305eaa342246813665353f9

Manifest digest:

sha256:72b61bf9bbedf939568077e0567d3399e948fb93aab470fabfb62a8bd91d7d21

Size

14.62 MB

Last pushed

5 hours ago

Vulnerabilities

0
1
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.14

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.14 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:782964f8be0a63001839192776384c79226ab4a222bc55e1bca44b060333efd7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:f731621fc9b83a0e5df6c8e730976345bd4756789586f50c09f74096c1d1e3c4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:01a00860815585fdc940fcead365a20b03f29f61142c240015bdd6f085ca78cf
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:4fa57ccd408fd6a5be6391cadc02b41b4f6485f460a5ddec26ab5efe17d77389
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:9393035905c88bde87be526f947e9e9b60a524283a68d0911fa33fe38d2c5606
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:451ca69861400fd8c3fbdf65f5731215f6fe701b7805764f88f313f967717dad
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:d67e88eec43c4e1985db5af1da210a288c3e988615104d596c73fd6761156e16
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:b1ff189c462c4ebbeabd914ac83484998d04036dbe46204258d9e78a86496368
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:6c5fd9886828350197ce6ca04b0420767aa716f7ef45b6b46393bf3ef13f724c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:677447ca343d83f8bbd60e3ac95f8dee960e66b991dd1e47e78bb9a076ea0505
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:1b111799232f32fc66b47089f245b5a186333e5a3e6243544b5b5c0a334aaa09
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:b46dc254b1aef98b916649c1abbd765ed0d56e01f88cc5b9fe592f3cede75174
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:9e231f72047943c1e84c8f88b41dfb50fba302827444b53e1a55f4b1a40e782b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:71cb2896e051c30b6c149786ef817ddad44ba20880a1cc4673c6c1cbb3acf838
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:ed82362f1b3daeccf113a87225447a32715bddacd500c09c54cd1d0a1241909b