Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.9-alpine-fips-dev, 0.9-alpine3.24-fips-dev, 0.9.0-alpine-fips-dev, 0.9.0-alpine3.24-fips-dev

Index digest:

sha256:9af21cb6260ece159fcdc6c9ee233e505fe173372748fe6af2908854aa5f8307

Manifest digest:

sha256:321b198ddfae0c7c4562f8aa83b9acb4309f5b6582645db6f18bc20e0d3ffec4

Size

41.43 MB

Last pushed

17 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:8e03c0fbba80c6c1f0a18b1b18c7f3698370f0aa262b4d08938ab96fab8dba5d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:6b0ec8e44c34ba1ad6dfb9851e785f642261065dafe6605e78261ac2ca112760
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:3758af96e7ce1ea8ec5e50807babc74e9a977ec99b24dce023545a72644e9ae1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:fdb85cb7468761f41db200f528842ceab4c421a983e54a3537f9f9e388a410f0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:9ee67c17690f22e1e7bd0dc3aebb8cf50bfc7c3d9d1a66517ac9f00550d1468a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:fc0f86cab38896403d9660a2f6a8e5c81327e3504c06baad5dc16f4422ae8b21
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:51222aa807ab1fab6a617cb407685c67c858d98c95fab61c7117263b27ee671d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:0fc45e6c0dec5189f6c4993cb86d470a50089455c249853f8577be29facd1fd1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:77beb7092de14813febf3d57e4d32dfa15e29d237532f43472b2e9e22a26aa01
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:5bb6978af5d76fde3cd43d1dc55c0d3771399cfa329524d89dae247b0b4505e1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:b54d6e24c7d4a85c7d877c0c7662f26f76c6de264c894e5a2c7a85de673e7a00
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:e94199358bda8ab14a302ed47268bd841ce9cc8a38d335b10c9f7dff2c5e7d98
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:7b76b49bd8cea12cfa2f76e5a78fbdb59f8b00ef59f44aae8c75be051e1a696b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:24029ab7958c104981d4416b691be74bf9aa69a4e989818b9f20d53c5a3266ad
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:d08e39b4bc2097d95ac47a0f13aa8cd9766662e9749c4052a193fb8e259abe6f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:f4d1a0e9377393736b327fa64ab8291b0daf9a4c16cc45df4e1fe88c3e8a6501
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:2d9163c9fc589ebdaee032091a1a0e9649d02c0d6620c383bf67fe30b5fefc32