Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.31-alpine3.23-fips-dev, 1.31.6-alpine3.23-fips-dev

Index digest:

sha256:820cdc8d7bd0ad3a4b0988c2a7170d85406b7a42d73d46a451c6e68fbe36d984

Manifest digest:

sha256:ea35f5252cc5ebe811a36b91354f71c85d0c61be2e6534654e315ccf530d2de4

Size

5.49 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:7f003e09ab68627155b622c30e58df4f8a1c227890d9f203704b7c6010bd0b6d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:551cd8b03843aa6a1902fb2cb2ded60dc5cdb7d82868ee31582151be763b434d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:d1627744f88fdd206449efb64822d37ab34c6c6645dc60951c21306545ebafa4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:2f8ef9e73aab32c344c7f40f95520b10dd96e6bdea50cc13f1ac3ddcf869acca
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:e801f0f202ef8a59de63ee19212dcea0feb9be9966c775e1f532eb3141059ac7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:a49db09a6ef8b69bffe799a908e0cd7fc2ade3d93da9b5d268e56b656ab2269e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:1d2fcdff7e3de980b175d0615231cb933177ab09727b0da6653fe4a201c6c2a7
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:7b3c947e5ae164df21e32b48debc76c8282b7dc929e2f3dc99870084c6dcc99f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:c4e2794975b1277a2e9891121035fc53387dd87f55abcc35783b4612a3b507af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:0fd5a190d91c40fa5f0fe24b814d9bcef10fb031012428b1df09bf434bc5b5f7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:7468264c7ebff65bb4440dbbc6dfb67edbf8e186b5b4185594673150c4239a55
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:886894a5edc8021abb5aa1d72448ced191fc08aa083a07488f5d4e7c8a10ed65
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:3c5ff7ffe70531d0af6cb61f9ff472f1216b9a2148459acd06ac786bc9c6899a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:12ff38a4d5def54b3ed5fd12f21f5dc32889b7a12a5112216cb44d600545d61b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:4c0c6ed9e8232b84c6245eb064bc6b253843d56074d3fdcd8971605b042ae589
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:cfc6f7a11b3023ced7a538c600a0d4679fdd51d6a1f01ca3da82fbecc5d16f88