Sign inSign up
SPIFFE SPIRE Server

dhi.io/spire-server

Spiffe Spire Server 1.13.x

CIS
linux/amd64
debian 13
Tags:

1.13, 1.13-debian, 1.13-debian13, 1.13.6, 1.13.6-debian, 1.13.6-debian13

Index digest:

sha256:8e7b47d74aa8d5f1939296347f5fb68acdf53cb614022b9a87e22cc3a0a0a484

Manifest digest:

sha256:a29ab9445994d679ebaef0e27b33afa966f247da79f8c122d1c0e300c3569016

Size

38.55 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/spire-server:1.13

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/spire-server:1.13 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/spire-server@sha256:f2e5ef926aec37611853e5ff7067a2ec5648371094a74a76e5f67cb8d7fe62f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/spire-server@sha256:4573535207a5b7b60a71c79b69548d2c1af23489f5086a801f6b5cfd8e0df10f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/spire-server@sha256:a14d1baeb71fad5fba1d45dfe7ae530e6bd57d7cb5692ba5003649cf5727571c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/spire-server@sha256:31bc54db4fcd2361f4bda72b6843860fe540bc2d79e9f653d2bac3b0140c954b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/spire-server@sha256:bd1cc4bb2e5579fc5606fee3a16b5f7d409ef0e1eb6d86111b9e8b3cb74bac9e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/spire-server@sha256:6da02d9b3bb0f242164abd26988c232813c533a47c1c04ae10064f2bbe96fa32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/spire-server@sha256:369da2daa03252e3ca9fbedee0ded7be83895dfbd432fdd08129ceb9a98533b8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/spire-server@sha256:815a6a3311446a4463ad8b8494726a171355cc5e394760976a0b0b313d0d25e3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/spire-server@sha256:d5c9865313ea74a0b6124489e1328152fdae10a82dd7a33816591f5ec2369b79
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/spire-server@sha256:523bc7ef87dbd1c21df3d53bb270ba703d63d634cffaeeac974498c810b83d99
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/spire-server@sha256:7bf2d0d3d8926718054f6832a06bc5a257142688152350cfaefd15a663147876
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/spire-server@sha256:fef416b7b8b1a737f823398b8157bf7819b396852c0d2a4cf175392c6ad34c9e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/spire-server@sha256:9fa52aa9c9cf606c9904707ac942fde063bf2b41a57f348c0e2ae1c18920c419
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/spire-server@sha256:e800dee73a811c2ec679bb52489504be8a32f929f5e0c54b0b548a295f923d37
SPDX SBOMhttps://spdx.dev/Documentdhi.io/spire-server@sha256:44599310637b40168d5118e1d213141df28e43183b5c199b449c17522b55ba4a