تخطَّ إلى المحتوى
QuenchWorks

authentik

صورة · Secrets & identity · standard · v2026.5.6

D 23موقّعة بـ cosignSPDX SBOMمنشأ SLSAamd64 · arm64أُعيد بناؤها 2026-07-28

Self-hosted identity provider (OIDC, SAML, LDAP, SCIM) with flows, policies, and application/provider management. Built clean-room from source on Wolfi as a four-language image (nodejs web UI, Go server/proxy, Rust worker, Python/Django core via uv) on a hardened nonroot base; FIPS mode is not forced and the license-gated MaxMind GeoIP download is omitted. Needs PostgreSQL and Redis at runtime, provided by the chart.

البصمة الحالية (التي ينشرها المخطط)

sha256:ae674559d1ed7cc9820d5128c914d5647f36effe3f3fed632e886946fcf5f634

تُرفَق التواقيع وقائمة المكوّنات والمنشأ جميعها بهذه البصمة. ثبّت عليها لعمليات سحب قابلة للتكرار ومقاومة للعبث.

موقّعة
cosign بدون مفتاح
SBOM
SPDX، على البصمة
المنشأ
بناء SLSA
المعماريات
amd64، arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
حجم الصورة
229.7 MB

الإصدارات المنشورة

1 وسم

كل وسم هو فهرس متعدد المعماريات (amd64 + arm64) مثبّت بالبصمة. موسوم بالإصدار، وليس أبدًا :latest.

الإصدارالحجمالنشرالبصمة
2026.5.6الأحدث229.7 MB2026-07-28sha256:ae674559d1ed…

تقرير الأمان (Trivy)

D· 0/10022 fixable · rebuild clears them

تفاصيل الثغرات

authentik 2026.5.6 · 23 CVE
الثغرة (CVE)الخطورةالحزمةالإصدار المثبَّتمُصلَحة فيالوصف
CVE-2026-39821HIGHstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing
CVE-2026-46600HIGHstdlibv1.26.51.26.6, 1.27.0-rc.3golang.org/x/net/dns/dnsmessage: golang.org/x/net/dns/dnsmessage: Denial of Service via invalid DNS record parsing
CVE-2026-69244HIGHaiohttp3.14.13.14.3aiohttp: AIOHTTP: Denial of Service via malformed HTTP responses
CVE-2026-69247HIGHcryptography48.0.150.0.0cryptography is a package designed to expose cryptographic primitives ...
CVE-2026-69249HIGHcryptography48.0.149.0.0python-cryptography is a package designed to expose cryptographic prim ...
CVE-2025-15366MEDIUMpython-3.143.14.6-r43.14.7-r0cpython: IMAP command injection in user-controlled commands
CVE-2025-15366MEDIUMpython-3.14-base3.14.6-r43.14.7-r0cpython: IMAP command injection in user-controlled commands
CVE-2026-53877MEDIUMDjango5.2.155.2.16, 6.0.7django: Django: Information disclosure via heap buffer over-read in GDALRaster
CVE-2026-53878MEDIUMDjango5.2.155.2.16, 6.0.7django: Django: HTTP header injection via DomainNameValidator accepting newlines
CVE-2026-59881MEDIUMaiohttp3.14.13.14.2AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...
CVE-2026-69243MEDIUMaiohttp3.14.13.14.2aiohttp: AIOHTTP: HTTP Request Smuggling via WebSocket Upgrade
CVE-2026-69248MEDIUMcryptography48.0.149.0.0cryptography is a package designed to expose cryptographic primitives ...
CVE-2026-71554MEDIUMh24.3.04.4.1h2 is a pure-Python implementation of a HTTP/2 protocol stack. Version ...
CVE-2026-48588LOWDjango5.2.155.2.16, 6.0.7django: Django: Information disclosure due to improper caching of Set-Cookie responses
CVE-2026-6879LOWpython-3.143.14.6-r43.14.7-r0python: Python: Performance degradation in XML processing due to quadratic time complexity
CVE-2026-6879LOWpython-3.14-base3.14.6-r43.14.7-r0python: Python: Performance degradation in XML processing due to quadratic time complexity
CVE-2026-44405LOWparamiko4.0.0غير قابلة للإصلاحparamiko: Paramiko: Data integrity could be compromised due to SHA-1 algorithm use
CVE-2026-33818UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Enforce a recursion limit in Unmarshal to prevent stack exhaustion whe ...
CVE-2026-56853UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3When a server is configured to support unencrypted HTTP/2, it reads a ...
CVE-2026-56858UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, pathological inputs could close an unescaped '/' early, al ...
CVE-2026-56859UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, DecodeElement would reset the depth counter causing it to ...
CVE-2026-56860UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Previously, resolving relative paths containing parent directory ('..' ...
CVE-2026-56862UNKNOWNstdlibv1.26.51.25.13, 1.26.6, 1.27.0-rc.3Handshake messages, such as KeyUpdate, are always considered as state- ...
0
حرجة
5
عالية
8
متوسطة
4
منخفضة
6
غير معروفة

اسحب الصورة

شغّلها مباشرة باستخدام Docker أو Podman أو أي عبء عمل في Kubernetes. تعمل بدون صلاحيات الجذر، بنظام ملفات جذر للقراءة فقط، ومبنية لـ amd64 و arm64.

اسحب (وسم)

docker pull ghcr.io/quenchworks/images/authentik:2026.5.6

مثبّتة بالبصمة (موصى به)

docker pull ghcr.io/quenchworks/images/authentik@sha256:ae674559d1ed7cc9820d5128c914d5647f36effe3f3fed632e886946fcf5f634

الوسوم

2026.5.62026.5.6-amd642026.5.6-arm64

الصور موسومة بإصدار التطبيق (وليس أبدًا :latest): فهرس متعدد المعماريات إضافة إلى وسوم لكل معمارية.

إصدار التطبيق
2026.5.6
المعماريات
amd64, arm64
تعمل كـ
nonroot (uid 1001)
نظام الملفات الجذر
للقراءة فقط
الرخصة
MIT

تحقّق من سلسلة التوريد

هذه الصورة موقّعة بـ cosign وتحمل قائمة مكوّنات SPDX SBOM وشهادة منشأ بناء SLSA على البصمة نفسها. تحقّق من الثلاثة جميعها بنفسك:

# 1. signature — built and signed by QuenchWorks CI
cosign verify ghcr.io/quenchworks/images/authentik:2026.5.6 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 2. SLSA build provenance — which workflow built it, from what
cosign verify-attestation --type https://slsa.dev/provenance/v1 ghcr.io/quenchworks/images/authentik:2026.5.6 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

# 3. SPDX SBOM — the package inventory
cosign verify-attestation --type https://spdx.dev/Document/v2.3 ghcr.io/quenchworks/images/authentik:2026.5.6 \
  --certificate-identity-regexp 'https://github.com/quenchworks/.+' \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

راجع دليل SBOM والمنشأ لقراءة قائمة المكوّنات واستخدام هذه الفحوص في التكامل المستمر.

الشفافية

تحمل كل صورة قائمة مكوّناتها ومنشأها كشهادات على البصمة نفسها، قابلة للتحقق علنًا بالأوامر أعلاه (تفحص الحزمة وسجلّ شفافية Sigstore، وهو Rekor).

المشروع المنبع: https://goauthentik.io