Sign inSign up
AuthService

dhi.io/authservice

AuthService 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.1-debian-dev, 1.1-debian13-dev, 1.1-dev, 1.1.8-debian-dev, 1.1.8-debian13-dev, 1.1.8-dev

Index digest:

sha256:b4484d89692bfc4d34fb478e51251843a0e6968d6d8a0973841e0a3fd4c5aa41

Manifest digest:

sha256:a100ddf0fee91101f8bb48379783a772220346e00be358b909052969d6e7ab4c

Size

51.34 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/authservice:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/authservice:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/authservice@sha256:4d8743f1797f97a3b0e80ecf5b5e53871510e10c893444ed8b03f5d55a4dbaf4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/authservice@sha256:ebc37960b2cb78f92c7927985823703f30dc2912fcae8c976ca523d9bb7122f4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/authservice@sha256:551e5aae244f14b0226a631aba7756d76ce8669381473fe5f1d2e4eeda49ddf8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/authservice@sha256:98bf4792f42f96ea4ced064d2d1eda0e7ce8f5b72052059932d61e18b80186e9
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/authservice@sha256:520ace9a8d6975cf06f15ea3e08acc61e80bc1a0e628530d1c66677a3d29aaf6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/authservice@sha256:ab803e04d66af289f8d4b828539ea16d500f6b5252dea4a6d3ee684a52e689c9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/authservice@sha256:98197c8bb5d494d7628688dbead61329824cefae8c1870bfb5a3a907a6bb5129
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/authservice@sha256:3b8d69d1341e809077a6455256874a59274bdc9f3a30832efeab96bf1cc40086
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/authservice@sha256:8bb32aad96b3ba396a9a77421cd1b2790669a9fe3011a6ffb1feee932503399b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/authservice@sha256:87dfe9388de64bc888f0577d59cc3261e263549f6df3dbab7204ba87e89ceccf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/authservice@sha256:a86a8d4f904d9cf6a50ef3bd5f7b4286b8f458d77cbe826c4f6f5071324f0883
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/authservice@sha256:808df12de3062aa5faf9c7c1d3a0699b89e9ecf67bc20f9b8f3173396a4a11d3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/authservice@sha256:04ff6e0d623cb8372888688ec9187f75c449e116462959692b0269abc7d1566e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/authservice@sha256:79c5f9344982dd920d1b4eb13c2e5c4f23f47f122494740e4c04e9fcee199825
SPDX SBOMhttps://spdx.dev/Documentdhi.io/authservice@sha256:d19e6791de39b8b593e1bcc3b1c3339faf0d300ea92bf41ffc38ce1df67cd767