dhi.io/dex
2-debian-fips, 2-debian13-fips, 2-fips, 2.45-debian-fips, 2.45-debian13-fips, 2.45-fips, 2.45.1-debian-fips, 2.45.1-debian13-fips, 2.45.1-fips
sha256:cee90cef8ac27959151ee37308f623d0884591aed8d6c44c5694f7cdc2273aaa
Manifest digest:sha256:562d024f17e5f4ac36f6329ab0bb92b1cd659373aa6e9bcc753943600d57e54f
Size
46.23 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/dex:2-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/dex:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/dex@sha256:471dfe9f72fbe8615127296de8cc3ac101cd3d3c9ced621f8b65ceab4751b72d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/dex@sha256:b8f18c0915d0de3109a38da773ab917ae4eba688b1062f69f2748f57c733c660 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/dex@sha256:a784ee56228b69a25fb016e86da46faab493aadc2dc6ef59919209a6af005023 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/dex@sha256:59a7899f60695e74622203a6bce88e9ad2f8584ff05de79d8ae5da4fdc1b2409 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/dex@sha256:b4496fbc8b8bbc43fc02fe9e5178745b09e6764da32fc1c11708c10e450905bd |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/dex@sha256:d4744dc5ed7d08fafde328dba3e9af7bcde67bac0111dad860f799ece92765f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/dex@sha256:1209763664de67695b4b54def5602414d3d920f05c78ada27c471d7bcfaa9dc8 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/dex@sha256:17b2b6ee9b36e0d871c80cd839d2a166417fe3f83826f1ba6e1b2037e2e455d5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/dex@sha256:83e1e1f07b54a6521a1a4f3827fa96cf85b7d3259799f9d2ba153b960bae4d95 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/dex@sha256:68933105f1030f18f8ab284542d4a1a29406718b6281649815aa663f29bb9ee0 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/dex@sha256:4f1dc269bec128c885af5cd63f486acdebd2dd2481a8b293364dd494baa0e66d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/dex@sha256:eab14b585764f266683036f467e61cfb4a7b40b861a77da4e5369cb6408502dd |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/dex@sha256:7f94ce17f4466b02a0ff7bf0f2e85ab5a0a8e7b9b59fbba7e28d99331b3f6fcd |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/dex@sha256:6a55b8a0368a8da767e1e02dee0b09ad5cf3246dc02ff4b600d9829c1072908e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/dex@sha256:9a72fdcc816a7873df921bac2bd17b60489e21b407e9c4d939242e94aa72ee1d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/dex@sha256:b7e238f9417ffe60a7a413926a61634eb2f3c3da85ba6366382574b0daa357ee |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/dex@sha256:1b1414b1c449901935413314fcfc55385ae66df3beb40c59ecd86a0eb25c3cbb |