Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.15.x

CIS
linux/amd64
debian 13
Tags:

1, 1-debian, 1-debian13, 1.15, 1.15-debian, 1.15-debian13, 1.15.3, 1.15.3-debian, 1.15.3-debian13

Index digest:

sha256:37a7fcd7835ebca43a8c284989a26cae700fc74531a31e04862ce39e472ffe93

Manifest digest:

sha256:04a37f6ea608b91cf456ffb16583941fda3ef2f181688f60a0c586ac83091815

Size

39.05 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:3df33055c55fee78c51ef7c007ae2a10e90481b29429cc2cbe672f01dd80dce2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:1086ece0af085a14c5aa922ace94aa718277dbdb11e2c868d636bbbabe4d3407
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:3b06464e18dc1e8e87a62b76a0bd98f07aabd4b68f6898919423b6ee1614babc
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:90bd44400bcc4d3a4403dc8b84b879130535db2c0b05820a78acd94583d096d9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:3b049b19095e705396b916aa2d4226a9410f9b4514158c3f6ee89b596ad77c9b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:c8cf6572f8b6be6d88aba7e4868182926c4df31aa26c0182ddcffd835c93046b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:f80f42065b66e4d66f45d6e30eef72b0f17678b655af78ac695fde0d29d3ba81
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:6aab91f7059b37516e4fa8237c697985d97d77811f05a56dfb33d64fc22496ef
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:7be4b657b700af4e083c2326e075d9e1af58fff63ad46f7ff9c8a2e1b998814b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:fb26764e7b91f40a973cf51e5ee94e6226278c2c83dec372622f29ee74b91e3a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:07e00173b20f9cf67521391bbadfb42e56fa6657bd37980a544014e297ed67f1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:bbf96c24049cee0cea84d72284ac10f14b35dcda1bc18df1d205d717367a3428
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:577cdf300c61a50b9d62ddcb58741661ec0c19a1e2c2bb1344a75b4a8a12c398
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:7dba147cb5b50747a322976fa67cfab2c8a6bc4e5d6e8e7b2f25957a28abedfc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:3887b7d6ceea9099463a7f22e263921ff03012548c9f93108fe87705f60a8644