Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.9-alpine-fips-dev, 0.9-alpine3.24-fips-dev, 0.9.0-alpine-fips-dev, 0.9.0-alpine3.24-fips-dev

Index digest:

sha256:d920a230185ad286006bb35e99788434ef14e8139aebb326406f6fea51427ecf

Manifest digest:

sha256:55ca115cc00c39d63473f85b61e2c8fe5c28e9701876f23ef82ec9bcae5c7d53

Size

41.45 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:75ab9c6cf92ce8304651b175db67167bfc8095859d51a0df9d2e167c0fbe88a8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:f22b2cc2f20527f6543cfa2561a5739afec2cf7171222d05cd6d1a326613d927
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:57252c50a79ad5946ccd034e5a14b89c5a60a8ff9c0d81f5da0fd7cc8985461b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:7ae2dabe0c83e1b464b4cfc478b9f269b280fed55270474cb5b184b164c75250
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:41c858fe2fefdd4788d0474d824c87f1d01481f66442a3f29dd7ff126e60129c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:8ba33dd2dfe11f00c0669e3bda3ef319e70a96dc4149c2f1162c6f0591f41e7c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:15ff18e7e7a4d63f139e4088e1a5a0e856f186bf6836e54f019e2a67c9feeccc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:7f23187acbcebfc48f3890ef468d421e7be9fe480b1aecf5858c2a2ed494bc02
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:0891cb065b77aa473796b359ad201bff59d13c27f97d06bd0494c70c649447ae
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:4e88179808da94041eab6f5788d86f7975b1e9cbc28a9da4361d2ef1084ccaf9
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:54735601e9f301ac1c4cd0d3c684ed1b9b74260404cb4d31ef374c53373ad93c
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:ec0520c8a0bea19c96078b50cc731cd17cc2ef9c3153b0a8e82f865dabf2ff4a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:ceb9adf8d09666b69f81e6fe27aa31c10ee32cea12b09363ea5ccac866083fec
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:721f761b090bd41bbba39f9bfd5770861fef7d676b46d7a0da87c0f6e181a164
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:5752584f52346d8a8aec3b82f34350a5163493ad49522208f053a364ba05aa9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:1423203df8433878f4f36d1bae2c90b44ca24ffaf6e0228d3be19db613a0930f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:ca2b7043a8b4f68be556e75bf76a991418b23e52bfd60405b3ce6360b86d4063