Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.15.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.15-debian-dev, 1.15-debian13-dev, 1.15-dev, 1.15.3-debian-dev, 1.15.3-debian13-dev, 1.15.3-dev

Index digest:

sha256:748b26fab3202872e3681885ee2aec4624904a71252a6336c69119daf4837cce

Manifest digest:

sha256:effe81502486ca8ea96c7ab85ac34a28868283975ee5a458ad91df64caa5790f

Size

60.01 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:067a1750107c6c6636695ce435feebdf330c57fbdbe24beebd8f518129d98517
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:c07c7b4476e449689e37186e5ce41f0338be8c8871525d72337cb81174274076
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:f1b2433514a0484df5e2c524b01b560bccef1b621b7bf2edb3ee425fb9ada95c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:79f317ce60f87e2c3f7c489acb16658a813b029b7421c2ca141d6691f1d7cea8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:bfcd56c771d1505273e8c322131d02fe3ca71245b5ce01be3ce6c2805741ae8e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:7b2797c3d227d130cc9c6ca37916d5986594bfe3c25a5c8c9997a5403811905a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:62940be031d984afdea15a217c532354429ba62a85f2123e16cfe8495ee10ae9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:b4459a6005557d680422beb35a6d92a993aabb3be00de069fc8aba9bb99c155e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:b1463046345d6fb889bebc3fbb907f6e06b21abbfd6e94f400c494edd05fb09b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:1499d6b6b53fd0de9362aeeb0a02ec36372b0b087d9a18f536a34150106643af
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:619993391cc89ff7149a8cb1008bf4d98657e23135be612e19fccc8d3e53d837
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:65d47c94b340e5aececd448103ca414055f211de2c8842e79b4a7d7ec9618a5e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:f848b9e6f71ebbb79cfbc33da638671ae92fcb9fc7609a995eb49239e0fee47b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:68a3f290970456b3b7fb1733008473bc9f2e0b520b05c2d86aa9f6dbe6eb4825
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:e9846e1f5aaefed65827e5ac710effd929d9e8ea8c78584af71edd8495cf29bc