Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine, 1-alpine3.24, 1.1-alpine, 1.1-alpine3.24, 1.1.8-alpine, 1.1.8-alpine3.24

Index digest:

sha256:9c61a992422e09b5252bd925b5d3bfcd39cebd2c1636c3ed7484c02269cd9265

Manifest digest:

sha256:36e3b88b7ba8670fd6eb6fe6e02812d140bbd47c098c000dae531c5e345d7e95

Size

14.29 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:95841349144821faa3464fa20447cba4a89ba1c0f0c13b4aec4cee849af5757a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:22651faadde2e43225121ff573083dc439d504179c849f78cc86e0a7bff7a4f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:76dc8c7ca53d8aa1188eb5cd7f30e712f08bd82d5d6ab9e5308c28a312209027
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:3eb6da5c4ce47af51658d922750dc5affd010ed73c54d79883d26b01b380afcf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:64be1085b1405996f5d77e5c68e513a721ed28a2e007450e3f268bca37d4255b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:da4e737f1a00e0b8c4d72baafe8c071cf8e98d3e474b2cd588039d44d59427aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:998523911a43a2a7151d2cb8fffe8a4a82cd28840206d149705b41a7f5f20557
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:30f67cba20a61b3f19239ec7723cedd4c5d90beafe986c3ab32110dd739e6828
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:c0c57c0f7fcf6bfeb8e5926b848adf9fe92223e784f49c9168ca4694cc1863d2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:a98772dedc439da9dddeeddfcbafea78265d1b8a7e003e53b365379ccbebf6e3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:82313bc62aa57ff246199c445d7a0005af2fb1b13c96536d8e4f9766a4712f3c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:96c458405f573d73c89ab5f19348829e47214a61a379329cd22bc890b85cd17b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:9da41e7922959c913b72ecab5e4f6eef3d42f43ecbdff9fb9569738f7f417a02
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:ed6c9bf48220fa30a0b09d12fd4b409f9fba79b95b5e647ef2460fcbeb8be58f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:4d9a189c46a5a50c87ed0ae6291bf0cb063ef595d2dccd24bd1a3b6805be9aa9