dhi.io/nginx
1-alpine3.23-fips-dev, 1.31-alpine3.23-fips-dev, 1.31.6-alpine3.23-fips-dev
sha256:820cdc8d7bd0ad3a4b0988c2a7170d85406b7a42d73d46a451c6e68fbe36d984
Manifest digest:sha256:ea35f5252cc5ebe811a36b91354f71c85d0c61be2e6534654e315ccf530d2de4
Size
5.49 MB
Last pushed
9 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nginx:1-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nginx:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nginx@sha256:7f003e09ab68627155b622c30e58df4f8a1c227890d9f203704b7c6010bd0b6d |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nginx@sha256:551cd8b03843aa6a1902fb2cb2ded60dc5cdb7d82868ee31582151be763b434d |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/nginx@sha256:d1627744f88fdd206449efb64822d37ab34c6c6645dc60951c21306545ebafa4 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nginx@sha256:2f8ef9e73aab32c344c7f40f95520b10dd96e6bdea50cc13f1ac3ddcf869acca |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/nginx@sha256:e801f0f202ef8a59de63ee19212dcea0feb9be9966c775e1f532eb3141059ac7 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nginx@sha256:a49db09a6ef8b69bffe799a908e0cd7fc2ade3d93da9b5d268e56b656ab2269e |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nginx@sha256:1d2fcdff7e3de980b175d0615231cb933177ab09727b0da6653fe4a201c6c2a7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nginx@sha256:7b3c947e5ae164df21e32b48debc76c8282b7dc929e2f3dc99870084c6dcc99f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nginx@sha256:c4e2794975b1277a2e9891121035fc53387dd87f55abcc35783b4612a3b507af |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nginx@sha256:0fd5a190d91c40fa5f0fe24b814d9bcef10fb031012428b1df09bf434bc5b5f7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nginx@sha256:7468264c7ebff65bb4440dbbc6dfb67edbf8e186b5b4185594673150c4239a55 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nginx@sha256:886894a5edc8021abb5aa1d72448ced191fc08aa083a07488f5d4e7c8a10ed65 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nginx@sha256:3c5ff7ffe70531d0af6cb61f9ff472f1216b9a2148459acd06ac786bc9c6899a |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nginx@sha256:12ff38a4d5def54b3ed5fd12f21f5dc32889b7a12a5112216cb44d600545d61b |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/nginx@sha256:4c0c6ed9e8232b84c6245eb064bc6b253843d56074d3fdcd8971605b042ae589 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nginx@sha256:cfc6f7a11b3023ced7a538c600a0d4679fdd51d6a1f01ca3da82fbecc5d16f88 |