Sign inSign up
Dex

dhi.io/dex

Dex 2.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.45, 2.45-debian, 2.45-debian13, 2.45.1, 2.45.1-debian, 2.45.1-debian13

Index digest:

sha256:ea054466320916346e97345f6e67a347395ee065011b891f414661c64ab9c2e4

Manifest digest:

sha256:db4bba5d6198c5c2617cf4b34582d37863fb59f0c1b7b6b43680895f232b992f

Size

41.14 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/dex:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/dex:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/dex@sha256:84d519fdc39bf454691a428616f955b053c17477907937d6a592d927123c4ba1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/dex@sha256:5475d110baaa9d3251fb8bb28e30d0bd974c3ee61cbe9c4f8f4af23c0567fbf1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/dex@sha256:168945700237139c8163e1497c741a4b855e3642bd9bfde397fb09632bf752b1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/dex@sha256:a704ea586ea057f286e02f947d8f6431fefa706ce2f88ad9d72da2d9b4187c5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/dex@sha256:b7b7be0fe519cdd2be2c7a1309f441df73191e8d51f23d5a0a6857d0d9ab08b9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/dex@sha256:11eeb9fa2ee8be4ec3df619d3ed7c3f67403f9cbad7f827d72fde5ae419c0448
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/dex@sha256:c2c43f9dc50c18937eed5ee0c1efe1b1d70656b9d42dbfc36a35e00acdf98985
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/dex@sha256:499c40056470aa1264c12ced85c7216ebc18b58611eb4ff26b6f8efee856f501
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/dex@sha256:1ea1a1d0b9afad563ef903281a99688e21d3d07ef7517f1553669359a5962689
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/dex@sha256:c9c2a0f5f5da80f275be74dfe1a14eb826fc6c2132993cc832147a88728fd5ab
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/dex@sha256:0b0459ba3c1b2502abfd2139243751f7c5ec83a73b3b8b1450f290d5648488b0
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/dex@sha256:3d8ae46ad765486699a21c3b0415b7a788fc28929a67d4f013554db5f528db1c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/dex@sha256:efca377ffc64c219491a023adf021540e82cae96ee739090e14cc5ab52d5d218
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/dex@sha256:adf05a48856d69ef7e64af69adffbf6c8055ac8b80ddcb7aba8d7e9f7957b611
SPDX SBOMhttps://spdx.dev/Documentdhi.io/dex@sha256:1e4011f56bd24a3532d4dd45caad9d2f1ccb22e686a8109de3f1821b2b443d48