dhi.io/nginx
1.30-alpine3.23-dev, 1.30.5-alpine3.23-dev
sha256:70075f132f53ff3f086d2fb51f9093a8a6d9f758cc1e77799e82180aa53275f0
Manifest digest:sha256:2dfb985ed37abdf89f599cbe70f7eeeb10e69054063f522942040cac65afdeca
Size
4.62 MB
Last pushed
7 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nginx:1.30-alpine3.23-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nginx:1.30-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nginx@sha256:5941e70c09a23827dd5a7183780c24491c2b993fea0cbc43cbe83a997f379eec |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nginx@sha256:ce08ca90b91c56ee63c85450c42ac8af51705caa82c85eab438ecc6dbdc081f6 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nginx@sha256:2fbac7ea73d66abfda8b2d46f0b121b12608cd1baaa7d54712858681d03b7cda |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nginx@sha256:d9a7601da690740673c79d61fc18a6180dfb5ea6868e460b8ba3a778dd3c0e55 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/nginx@sha256:68de421c87425cd484cb98abbad5b8564e046a68f082c9e966f1438e4e87a290 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nginx@sha256:0668d75a4cbec5d0f4c450e8b13726df8c97198bf6b5428f3fd04a9f990376fa |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nginx@sha256:0f459074c9ebc878d33853bd403ceaab5c783f245424486f151e471571fe7d08 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nginx@sha256:4c90232c50d02dc9168178c2736817b0fe7d0d626f374ea0b57eb6d99220dfad |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nginx@sha256:0af68eb1a505bbc246264d639b89c342f636279ad5653b95d2783f959b1d74f7 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nginx@sha256:397e50f691092512d937f85864bfcb1e2a50c7f3d207f6c6f4106697f7d1b67e |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nginx@sha256:486548b94c906df098840ce8f6f42a31bac55f7dd3c6571fa6b3cc7d0b4119c4 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nginx@sha256:d568a7b6c07cf380d3d1eac902c6bec3b81ebfbe24bac48e9d56cb8eaaf3c349 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nginx@sha256:db32cb18ec49e3ee2dfff45d2253a62588c3c1cf836f9546b3f7f1f7492ee4db |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/nginx@sha256:eff2f681be17b4d53b8cc42fb4f3ff8c0d0c00d8fa26292a86c5ddd6698dbac6 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nginx@sha256:eff7641b7602fc2eb408bf834d241aa81e5df5393ce76b8127ee1ab09c9c3f0f |