dhi.io/authservice
1-alpine, 1-alpine3.24, 1.1-alpine, 1.1-alpine3.24, 1.1.8-alpine, 1.1.8-alpine3.24
sha256:9c61a992422e09b5252bd925b5d3bfcd39cebd2c1636c3ed7484c02269cd9265
Manifest digest:sha256:36e3b88b7ba8670fd6eb6fe6e02812d140bbd47c098c000dae531c5e345d7e95
Size
14.29 MB
Last pushed
5 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/authservice:1-alpine2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/authservice:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/authservice@sha256:95841349144821faa3464fa20447cba4a89ba1c0f0c13b4aec4cee849af5757a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/authservice@sha256:22651faadde2e43225121ff573083dc439d504179c849f78cc86e0a7bff7a4f4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/authservice@sha256:76dc8c7ca53d8aa1188eb5cd7f30e712f08bd82d5d6ab9e5308c28a312209027 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/authservice@sha256:3eb6da5c4ce47af51658d922750dc5affd010ed73c54d79883d26b01b380afcf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/authservice@sha256:64be1085b1405996f5d77e5c68e513a721ed28a2e007450e3f268bca37d4255b |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/authservice@sha256:da4e737f1a00e0b8c4d72baafe8c071cf8e98d3e474b2cd588039d44d59427aa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/authservice@sha256:998523911a43a2a7151d2cb8fffe8a4a82cd28840206d149705b41a7f5f20557 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/authservice@sha256:30f67cba20a61b3f19239ec7723cedd4c5d90beafe986c3ab32110dd739e6828 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/authservice@sha256:c0c57c0f7fcf6bfeb8e5926b848adf9fe92223e784f49c9168ca4694cc1863d2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/authservice@sha256:a98772dedc439da9dddeeddfcbafea78265d1b8a7e003e53b365379ccbebf6e3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/authservice@sha256:82313bc62aa57ff246199c445d7a0005af2fb1b13c96536d8e4f9766a4712f3c |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/authservice@sha256:96c458405f573d73c89ab5f19348829e47214a61a379329cd22bc890b85cd17b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/authservice@sha256:9da41e7922959c913b72ecab5e4f6eef3d42f43ecbdff9fb9569738f7f417a02 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/authservice@sha256:ed6c9bf48220fa30a0b09d12fd4b409f9fba79b95b5e647ef2460fcbeb8be58f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/authservice@sha256:4d9a189c46a5a50c87ed0ae6291bf0cb063ef595d2dccd24bd1a3b6805be9aa9 |