Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.30-alpine3.23-fips-dev, 1.30.5-alpine3.23-fips-dev

Index digest:

sha256:b3e0191402b38aee7eb9baa0ddb903358ba0571fcff6dc3e8224ee02897c9fb7

Manifest digest:

sha256:1c0b0fc98653819da3599681cedcaffcc2955dcceac05340f1b9df554194367a

Size

5.46 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:0530b516247ebb84e6f1a27bcaca4d926da374ba1e3196bad3b9c7ba78cf01e7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:7417032b12bad0fd5dda88ef0cebf2150b2e5d4da6939843286bf68dfbc055cc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:3a678f58db94e4be59cc8ba91505fe0466c40c50ec6afc1b8f10abee55d0a2d2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:93d26ec6eaccdaa7aae482da54c6d5419d78dabcdd4066ddc0f51dd8aa100789
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:659db37522cce81951402069fa1213412e9815d06ccfedef10e3389f58782a1f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:c93bc284001bb52634d230f8c395d5b97dd2d87da9d10402d21db1a5f496d08c
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:39d04e6a92eea9c08cdafd92fa5744f05db22bae7ed0e235bca8264031250186
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:158de2a878d0deab4d8ad61d49f75785032f88b3da46d5da2838d12c5917494b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:d71e3338abb38575c17a0168e3f9b5ca94d6b17e114ce0fba69c9f1635a777f6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:516dd0b8eaa1b1130b1276519a644b030f3632729260f2bb3abb929570a79414
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:40a817d7aebf8815043d80895e28119b413d84ed6f63f3213f26d6633f952560
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:8e1b4e209e8a36125320d22392ad54f6db1bfa4407a16c839063766d4c32cd53
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:d0f54c62ab4c96f42eeda12e59088e6973714919038f7bbccb61834c2f0c2d8b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:650cc085b67e84b6249d0b89560bf96d4c9200c126175aab6741b65f0d7c1646
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:e48137484dd470ce0656c451f951d39d6ab5d52d8c84bfe6f367808e80ff4157
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:3f12bcd0ecc7b38a3d955762124d0032db7ba3a4ee4b29fe589b87c5d77c6a07