Sign inSign up
SPIFFE SPIRE Agent

dhi.io/spire-agent

Spiffe Spire Agent 1.13.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.13-debian-fips-dev, 1.13-debian13-fips-dev, 1.13-fips-dev, 1.13.6-debian-fips-dev, 1.13.6-debian13-fips-dev, 1.13.6-fips-dev

Index digest:

sha256:8ea745198020f6e0b7f3e814846a9640afa4f69995692121575fd9f3e68d1d06

Manifest digest:

sha256:dc52e2734c0ae266b6d1da28d0f9ecf0857c8d09625d2a50441d3151b65d8443

Size

51.75 MB

Last pushed

6 hours ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-agent:1.13-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-agent:1.13-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-agent@sha256:5d78112887b79717bbc49012ac46213c44bf0fc939006f341bb4c2baecc010bd
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-agent@sha256:22e6beec79940436a421d8415d6d3c4b24427328be638b9cdb6285d3a7ec92b0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/spire-agent@sha256:cf91f5168d603e84f30662bb478f4f57fcf7ba7e12795751ab3bbc1bdff6e69d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-agent@sha256:441c7d2c5542a7a2ee2d764ea76fefdee0e2b316275f67f50e633a535be08983
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/spire-agent@sha256:355c6989485e3323301992808177db6f50c580ce4839889dafe6e95cd972de44
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-agent@sha256:618b112411501d4ffc5bdb603e3250d7fc1d235e49c26edbee3477f0ef99159c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-agent@sha256:fdebb7a483dbd78f99bb83e84964256a05c36049d7f448bb0f6e6e86e146cc56
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-agent@sha256:1c23d30c23c1881e47b6a8bddf4b887ff96b827c5a827dfcc1e0c800f2cff183
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-agent@sha256:57ebde0cfbf8a88e04b626f3a33d965574f7640fd3ba94e0ea3649618cd331a8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-agent@sha256:bf859325ca13615e7c9132b3c633e7eb0b82991e240604587dd023f53bfaabd9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-agent@sha256:d78ffcc13e7c1aef998801abe2490f961b4ffa0ffbf89dd63c880d11799f245e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-agent@sha256:3f1ac03f855f8263fbadab20f8b42134f179e4fa35a7bb7cd8cc5e0295cecab8
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-agent@sha256:abd4c22a0256caf3535642fc2886a915b7b2a35d03efec1e40229e6ad2bd12fd
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-agent@sha256:449d97a79bc02a48c368e4a0d2ea71e21aadcb260230f73edd80b139893ddaf5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-agent@sha256:c941bc4ecb17073246e40e2b44d5f02fe7fbb6a10230c0cb6f8e1c1e4c1388bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-agent@sha256:ce426d4ef6ad8e0e316b83c2867c92fe9696890f08829752cd6b7eb77b7f8e9a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-agent@sha256:2afb84e6ca3917387bc3aa09183d5978f04220f711548194670a2bab1435ff73