Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.15.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1-debian-fips, 1-debian13-fips, 1-fips, 1.15-debian-fips, 1.15-debian13-fips, 1.15-fips, 1.15.3-debian-fips, 1.15.3-debian13-fips, 1.15.3-fips

Index digest:

sha256:7ad3f397c8b9f07e0ebc02b3df8b0a192041e790f684e4b255630490a91da37e

Manifest digest:

sha256:cfa36e4c21d9360e8bab86e6ac81aa69389be3c74c1ca2b9a7a5c87afac21f25

Size

27.19 MB

Last pushed

8 hours ago

Vulnerabilities

0
3
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:7e8fd6ee935926bb16760bdc0d11ec7d2a0611162153571a5bd7670d9684cbc4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:fc9c651c5e3cb06d517e0583a3ed25bf4b0ef01954c0e24d16d0465b6e7c4031
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:c7140107be9b38d0a6461b1c388c0f9373092e2e5e69ce97d5cfe4734ad7673d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:7f2b7870de877b8389296b7480a8c1ea795b907e3495655e83ded725db699b43
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:b4d39416b05c40c937ae85c4dacb210b83e371ed5b602d8ede12a4550f12c935
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:68cc8be35eeb2de3910ce17179443cb6c384049d7650f84a3f2444980626719e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:5b55374e179e37a6ab194f9f5f27e26965a6d7d2698e04c8d5bb7c938bde9ad8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:74a3a3550783d3de95977b10d98f1e428e0a9ca5f58715d2020ceac3fa8fe654
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:83b67b7e16bb51bf30f36bb476f8437586286b4d2f5522f1f3f88087b5d1c7b1
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:19cf7a0c0aa698bdf4578408302d1ddecb1af8aaf124c335a2222716e2f29237
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:ec2e9b468f5cd5e745c5474ec96f622f9a39cf4644b0b29acc7ae7a0eb00f29d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:caf67afc93224e2beff10d765af423f5bd0ea906b53f9fc1de7f0b12b3edcef4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:3713e1d63d179f574cd443dab457a0b3f60152c8f3310fe0fb513e891fe26a74
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:cf0c4acfa61007635428c08a9f9805004889892f23b429d4c4d537f8a1043ec8
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:2edf076557699f09122fc5faded32a0bdfd11e2d8a361a42f7ba650898335ac2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:28d99011e187d5a4dd5a1f721ce4d99c03d01a15d0faa654d653e89d19de3b96
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:71f4c9ebd2fa13ff051304106ffe9c1a2e1e7f9b1d6e6e45a8af9a93a1e2c85b