Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.9-alpine, 0.9-alpine3.24, 0.9.0-alpine, 0.9.0-alpine3.24

Index digest:

sha256:acc28a358d327d0534dde198bfd9b5c09bdf2e73acae2f3996519eface23a33e

Manifest digest:

sha256:4681abfc6fc4de72dac4085cccaba5d68c6f399636e35c7936a241792e12cb57

Size

18.31 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:300b7f8721306910a3e52a920b73d0d7e90de03298f8c77a56c3c9dabce7b6e0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:b2387fcedca1d260b8e4ad819904ce5d1313eb52c0e9f8d95c35be38a24bfd91
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:3f0a86cc1d9198001a74588f68db3aa6a9da6b06fee5d1e5856f1b754dae13c7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:185332eb092a87990f5b37e5f388013446689742aa18df5f12bf91f1076f9424
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:b004696c19e3282f42d82b07ee6867f71a7af9fc41f0c7b00574ff3deb6e15ac
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:bccb0b2797d4bbaccac4ad446f30f183ce57293af81e98155cb72f0a514d37f5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:9efdee789ecd26d7cb24f7c612b5610e81a0ad5f9b293ab4afc5f591b4473eab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:07033d2c16c7c924fc8e5322c43ed5653b253dfc09672839851fdda7a7559938
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:b4f641c63345231c7e776980e152dae5f7ea17783b8d9621eb34930073d489b8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:a520e57e93fd56e29aba787ff749ab1644c65271f5b200f636d44ce073774554
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:dc77b421899ad897a5890ada0fea704c95c6546c195c68c80cbae549955dbd1f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:3eb78a382cd4ff02d80689fef37a8182e6781dd2bc4e86b505b8bb6cfe2f8279
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:b89c79d632012be8fcfa0d774442911abf61ae1150b4da9d954184a1f9f48363
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:e877f99255bd18fd38b2fd1f6b7c69f9bb0cec3fea07f4e59cd649db70196292
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:2ee25b49f08601245e4c36b4e1e8e58c5c78677795c54664ed7b43f5c46bc9d8