Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-dev, 0.9-alpine3.23-dev, 0.9.0-alpine3.23-dev

Index digest:

sha256:edc3f89d82a36ebc4bf4f1766d6a9b422645c9123df31e66f83a7ed4fba37845

Manifest digest:

sha256:9b56b6cde30f0600c86e4f9934273b3eaeab1fb10b3df188c52ee5b545565b39

Size

40.62 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:4ebb5ec9c1fbc83bd483ef5ed942ee777830ed199d9beda9f50527782ecee767
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:037145eedf777ccbb48cf7eedf712771b29e726afca69fc0bfaa5b33e02cca70
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:b3f3be6d606a8aa4c9a30b99605eaa6ab6a88bc7656722acda35d840e7321c09
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:9b604d0407fa94f54c8e835b301f3f7b72b0a9664e738221f598c0bca645dd6e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:bd6c1879ee2bdd5ef55f3e72e86e17f29f2515cadcf34239d6382392a8fa3759
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:3bb91af1a961aea885268d4536734b4cdf28adbcffb4300b5fa3a32d7519ffcb
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:c609a736ff13e27ec78d24fc00157ce93e72d1fa0aa2bdd9ea82894401707496
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:77a45504e17fac22d974da332f2b508767e05a4d1b41311891c7cc9934de9fdb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:6f3769c9d1e190cfc0f20c80e14c3552a199d87071dde9479d6af6314a3eb88e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:f239ad03248523fb5043fa9d096bb67ac981c1a5779ec1a20dee79dc7b7d1b3c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:16c1aa09d70aed8b7da305571a626f70a4e2cbd1cf0e3d0f3d232fb7cafe2922
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:5c497eb2db7d66e5cfed20c162037697be2fd11f1cc4c87a7b7e585cf8cfba10
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:df92e41af5abc8a7bfc3bcd2b45bbac06c437c12c65c7e0a63bc397f1df4c384
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:0afbee2e697e813be6d83120f61c93d6d09f5be2f36c9f90f2ecc21509c13ca4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:22312b15f1a443d01a8207739b6274136a669aee29c60b8bd02a3b16c31458c3