Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1.30-alpine3.23-dev, 1.30.5-alpine3.23-dev

Index digest:

sha256:97612845efd9470072a854dbf109695e64c3442228a86493e88eb098776a4706

Manifest digest:

sha256:1bfa5b0c10830f9d79fbc0296f4f57d9b944270b8096c103bfecb7a7e419038c

Size

4.63 MB

Last pushed

21 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:c02eb977cb21c1ac653dfd3ddd41572138428694136b95edaa6940676ffdf54b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:f3f07e961adc45fb3f1fe3fa04839a7d6c1a89d1b7bd3f1f9d61cdc7e3394e77
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:94f40cd5c9079fca123939ab40052cde97ed32a69fe82813b5956f9d702a23e7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:e3db877d5adec87b9a929bcdcbc999dffbf84bb0aac9abd4e929b1ee425ef5c1
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:f132dbd9c0b14fe9a54e4188d0b2be6f894668a31ed2b2a1d8d11142ffb3b30a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:cfabc396366cb9894b6ea63efae0fa077ed247b2737d2b4e009f2ac2c829010e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:c31cdf2aa41139b7d2afe05629e84516bb3fe0af3ce4c018d1d8070a7bc74b6c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:54e7e306d57031d494f0c934b5030f83806ec325c6eae302ccadd7a408a97c39
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:5fea548a946c85a33d8d3d6903d9655d0873a3a9690e0a7b1e4c3b4e2d7d1332
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:5f4b212fd67de415fe1fe65654e699b3620c84cd3ddfa0e94e3b65b775c154d6
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:c7acd1972f01d350657026a4c02008de0837245a24ed20e969b474e1da1721fb
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:48093287d6b762fc059e117efe6d98e7e2fe6fcb311e57c5c6dcd5c848793eac
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:5e5bf3a60f26087b1a3f46208545fcea676ebb8379e4738c80639eab970ed2fc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:f0f0b5ed43252245ad12acad24c5c8b40a71bc9b614a8c985316fd29f967d1dd