Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips-dev, 0-alpine3.24-fips-dev, 0.9-alpine-fips-dev, 0.9-alpine3.24-fips-dev, 0.9.0-alpine-fips-dev, 0.9.0-alpine3.24-fips-dev

Index digest:

sha256:aa8b7bfb120d2ac72a8d54f7e302d93dbbf7ea46663c4b11c9f932a39f0a1ebd

Manifest digest:

sha256:eb849d2c2995f4086a4d276c6065f6a75bd0ef423314f9404e43f693ca50d108

Size

41.44 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:6374f7cbfa6a19b7ef692fd41a66b7293f7afdc7eb4db93c6ffc7617b8d33874
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:6fa42fdb024f6289498b856c1db4de499c9e5aa8574839b2548696ba78b6f13b
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:16282f85d92ce24e26ba4f953bd98e102c4a5e9717af436a430fa000b1284e09
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:d34e6b896b563da22c817002523f1cdf3cf8acd8690701acdb0c33a1e8b78d7c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:f9eba232c72ff0d14f982fe605cabb73eb28b6dda613fad1758200279c979eb2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:e5e840413a719ee0a572e12f1f809bc47896db1d2a90b09dd299e5a482b86fa2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:aeb0c7f30f20df12199677bdea5d8e0cf96681c5af7afb4d18ef7ffde13c1e49
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:9c559d44b702177d80af0b963b35986febc52a6fde5ad57daeb49aae080b58c4
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:25ca2bc1a8571b925dfbf08c2826f60595adf1f8f320e1474fb5aca3370ccfbf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:58f59797c1f8487fafa493c389f2eb01ac15990f72a119e870d84a80506d7815
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:9478e49c8aef3ea52bd719d7052f9fb97f986794878f8a52347a1f2cb5553a43
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:6c4de0576e086dad70c4810793a7bcdb1e6fb6ca59aa4b8d5611a0c61406f966
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:6fc7e02e75b994f6d9e2f09a0cfae282b3f7939054c1a4dc1544fde146b36d31
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:f13324345b554a17de6a5237e40d67cf3b7ef6515206f2fb6af184c471691148
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:c845cbf89221cba576923db51cbfae44bb9dae7a59d7e8c3d2d78bfe0af5280d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:613f00d9d1c7102e03804634d0a94e41d8279effa2124efe425a181bd2632814