Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.31-alpine3.23-fips-dev, 1.31.6-alpine3.23-fips-dev

Index digest:

sha256:f3a7e34e59696524724c8040ee2e51ea0351b2ea52e60f39cd4aed7aded509e2

Manifest digest:

sha256:b3f52bdc1a484bed4ebefd9e501aba1c5f2adcc98e38f10093ad011de6ab1d09

Size

5.49 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:b265f06aa14b97fd8cd7b5e37511cce63b0da5eb98937ae8e836cb84548e913b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:919fa4726172990ab008e500c3bc1dc27d7a97e2c12a67b009f30ee65bfa2846
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:c2e0c50984d7741970761463aaa300f52bbbb0f2b67aa5f12279e43a9ae60d8c
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:e9156ab28a51a55083ad1c6bbb45a8872948c364fc719b0fb3496cd9f15e9fd8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:205ebf4ac0f0203bc8fe9bfed4078dba249bfad834ab535894e0f3c5b00215a6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:3f11f8cfd1445375591f8174dbe57fe1c6673a8e3ce8a157c3a3e04866c37700
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:e9ab444fa99435e60e94b0b0001c431141098117bc39bd3bb73f466ba91b35a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:a8ffc3f67a93cdff7ec1e563ce77485f615e9f5a723540b7a179952ff3744c32
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:e5315a9e80a2f95c55b4e20ff2b8d3c81f1659b55d3f6d4853f6d71496fc1362
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:5029f4cbaea5eaee85e7ad87f7610274373ac68e327d3e1eae22810afb60c881
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:dbde21ce5f4616736f76e36f9439b9ffb4f8796cd016a60156703534cc112e94
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:c0a65cc821376e84a967d78fa52c4a34baae2ae42ca90f2687bf19fb057c48e2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:d01d3bcdb72615ae4de597030be49ae414ba1f9799ef6abc097e7f0c332a4826
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:18cd1cb9740e59524bc14ce89aa23ef632a50bb2b062b05582f85088c4e57adb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:36666b9d7d902f55ca6be80b8a5d79ab1d26abfc9bd9debf4ccfdd9a430c6666
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:a234836c9f047f067bcf19c301507fc1339e4f6700645060532aa379461cf622
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:c1dab250c4c8655e9c0f7d54c0ece54205e675f21826b056a4264a8982ce38d1