Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.9-alpine-dev, 0.9-alpine3.24-dev, 0.9.0-alpine-dev, 0.9.0-alpine3.24-dev

Index digest:

sha256:9ce552bb47ee0812038d2c3db3ea9091a014ed5de0ef46a0a7bff1db0a67bc36

Manifest digest:

sha256:52f775746f5df49543c261b9086226f46b778d893fb4ab020048886c8a175fff

Size

40.61 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:928bc16306c1702211b9e97a0a998012cbc40815dfff49b3781d4c23a1b3ad67
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:7902ecea569252c8f57ce13ccd1f0c0b09b5cdf7a7498b03241ac1fd7d3c46d4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:6c07f94d670c34266be3e652e56d691253dc17f4d41cfca3038544ab0f921fd4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:de309e61886535eba64dbd0c2ccada2b880862cdc948a836ef2f08a5a36e3547
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:4c36a7145d89b07c734d5d0495426d77672ccb2284da7bd22d245fb06e521479
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:a400a7b6f308f55b5b5cadee79ae2cc126e0f40a33929d6129a5c7976a89ff9e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:3919e96b779a7ee45f34a1ca818315f08b9a63eb769ceda0c5d1b5cfef3f43a3
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:265128daadc8683d77107bfc7ae2393cdd1ebcbdb77d6e6e7e77a590290e0ca5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:597299ed3889ff8678c95400e0330423315c9853c218a19c2757388ee3d3b205
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:da4633818cbac4b2e151192bae99a1094c657eb5f51933e4c4517908952d789a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:2c64677c5cc30511ffc51e06f3e49cb207ed9eba9f5f604d665f0c09bbfedc83
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:42dbb3198b308b42402c9fa166caedfbccb341638167c9023315deebd19db691
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:dd1a16cfab73b98ada4703019757b1cec0761b5925d0769beec41e29a71c27ce
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:1f8a62552d0775a3e42e68a6f3f605494c049954face8688a7908a1f09de2c35
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:a5301190553a3d6c604b37cc6b2f0046744cf38779e76ae08aa3df12d187cfc3