Sign inSign up
OpenFGA

dhi.io/openfga

openfga 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.20-debian-dev, 1.20-debian13-dev, 1.20-dev, 1.20.0-debian-dev, 1.20.0-debian13-dev, 1.20.0-dev

Index digest:

sha256:a73b2f7e165e71f340e4fbe985f7b00a52ee0c82e41de8e4a04016ac94ea3447

Manifest digest:

sha256:bba47a4326ef0be56e2c0843570ca4e7506d5cc93d9aa03b596506e4eb1eea3e

Size

63.73 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/openfga:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/openfga:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/openfga@sha256:b18204533b0a322089b8fcaece834f7bbfdf6a9f0ec13a95347b472e29cf5ddf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/openfga@sha256:ba22af96bf514a5238bfb90f0a42aa943882ccc5742c79b0b421294710b44a99
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/openfga@sha256:791441e69f781ded4973fffefcb26c94e87549e03051fece5cb1743587d41782
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/openfga@sha256:2732ee16a5dc14e706d71e747e814c8e3d6cfd45ac43e15b843b6724c8a15ef1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/openfga@sha256:4124c7cb74bf1ed9407441de69e2d69da10e11b7cd019eb329dbb8de5c721d08
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/openfga@sha256:3013cfe88c0c7b7a1fc3e0415f384939298f26c11a815f27310889981c723af1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/openfga@sha256:c25b4fa792451f895fb87fa089aee8dc7694712302b8a1483593b93372dbc37e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/openfga@sha256:5fdb15c7775c6dba5e8bc54152c4581ee291c44e62e2cd01943ce7c8dbe56a75
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/openfga@sha256:0c6399a7841b45eb5a7aa9698cfe3149510071ba41486dddc64cb19ee5de9915
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/openfga@sha256:8bbfd1a3d5169ddfb82ed5330b2b081d83f2eefdcac443c4296126cd73f1689c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/openfga@sha256:92877cac6314dfba1b2838333ec946c87c7376ef4235718f460944b9c24fe2e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/openfga@sha256:13c4a9a1efb5ec11748ef0a3aa2eeda0a2d039a5e06f8d8f5a78988a48c27aa9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/openfga@sha256:4df58e604c4e3a0a0ff1a76321048ed710b57c4dcdbbc287a9a25ceb399f8dde
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/openfga@sha256:06a870520805346060e7713633a21409dfe9e9321333d9947b658bc336860483
SPDX SBOMhttps://spdx.dev/Documentdhi.io/openfga@sha256:3428e9055d98e39aa1e8c66e0d5b3942ee0497ed14cd15e618dcbfb2890cab9a