Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.15.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.15-debian-fips-dev, 1.15-debian13-fips-dev, 1.15-fips-dev, 1.15.3-debian-fips-dev, 1.15.3-debian13-fips-dev, 1.15.3-fips-dev

Index digest:

sha256:acd05de3bbdb3388bb131fd4c02b1d3f10dc0437e39470bcf35a20f51101358f

Manifest digest:

sha256:db4df7fda65af5c4b85808f90425e0553dc22e15e4afc8b1d5adf6cbfc57c767

Size

60.79 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:d9840d5f6485902a80c4b23d2365c5fbdec6cedfb5cd6abfbf2a0daf1b0700b5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:02c1557f6718c929543f2abae5e941dfd9e1728fc2d60a9dda16f6d11c10f4d5
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:0e09ff7bb93c5edefb4da581c2e7a8c8edcd5f646e4d35831f5c6fee32668a73
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:10eeefd552225b0d3dfb5d5526af4f635dc0b9c7b8ed5ad6486ca9f121b127ca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:3ed7d861034321b776c85b37d843f4be80c31963098827d6a7b7cf6a1476701c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:46d161d9ff7bbd905dd5bd82c27d0f788f147d8475a261817d2c7f473d4f241d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:6b3343614b5437e633c5b3c0dbece2c2d3d7a3e9b18e9835d0f010205b42d8e3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:63b1916cf35922cdf781172a9c01b9ab81af0b195eb0e083bada7062f01c183c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:2aff4f2c20d0c6386b8c84536ff34984badbbae1b42d817c902b52347aaa44e3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:2615e6120af700ede5e0603414601d535e56798aaf5f41aa1b708ce3a1880468
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:f6b28bf28f08d37b556432229561d229ed6b067a615310c9ec531c49e4060717
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:b312b84567c04d1a88a5fc8a5557f8374a5f414b0d2b46c39fb3d77ce0fc23a5
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:4fcf45778a1ff0ee4cf44d925dbeed3bd67d08624d6ce017bc2142c9ea392b28
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:8177ca3632713bf95a3c7b24585a711294b1d0e7f7e4a332f54d2fe1bb971a0a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:7d78b9fc07892b70587e9c01ea4c636baa7713f20f40303256d8be40fc86a81a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:e7a379e39a6b00c4daf545d1f016478d138e69c540d38a559ccbfd0030c17730
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:77d1bfb4e316015e8ab9fb8659d0e2efbded9428e070d8f4e0b76386a1cba629