Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-dev, 0.9-alpine3.23-dev, 0.9.0-alpine3.23-dev

Index digest:

sha256:79f6c2d10fda67753c0f47f2f56db7ea619a073aeb1e59315d8d6992ae66ad95

Manifest digest:

sha256:5d5322eab73f64b902f46cad0b091cf0677be39ac7fb5e759b07b1d641f80e76

Size

40.58 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:12d73c7e138cc91a706724b003df8ab486200c9bc9714d7e8fd032764ca1ea63
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:b252c2ff737748026f79d05c2342f80771e2139b7f5781240136c0b1c2bdddd0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:0c8d606b565604183ec9ca24e873d8a8b471da29e91a12af21bebd8e3af8dba3
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:2318745b48ca63be2c5c8d79e6f104ddad2a76bb0aa4af3ff32d54afd329beff
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:b4479f8074a060582f82542b135de1139176d674c01c046ebec97333a484d052
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:70562bc13bbb6432bbb6b8dbfd831338e175b1cd973a4c93a9749dd330721868
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:2b3996374118af80915b9b72f6e48f23af16c348f7b6ea73760cd55cb744da07
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:5e7081064c1b1dd21dacb638320f028b2a4f9dbe16587cef6972a971f8634127
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:5bb4f9da15af72e883306e110964ce92cfe30ae3c767f6f5f34056e9f9c11db7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:23751e7ea59048e9e73eee2f2848aff4339d142ce507d8600a9a5c777dac9474
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:97f7d4a4fb1aaae19ce3de75a7fc3b5e9e1130921ca77a29f13ad613ae3d6eab
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:8be0176a98cf6a1af4c12d583ed1396fe3698e958fe4d32b7982e382b0f6e4d4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:6d30dd345dcd2d3fbdfc55de79f64475757e9178bce5e651c6c92b9f433dd09a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:27f3ce798d062a2be66a3116f5e438f36570bb942b4090e9a505a67174b2cfce
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:b51ee16722da6e612fec5294f05abff06ae0f7e769790d2405a9cc1ad2185fa4