Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1-alpine-dev, 1-alpine3.24-dev, 1.31-alpine-dev, 1.31-alpine3.24-dev, 1.31.6-alpine-dev, 1.31.6-alpine3.24-dev

Index digest:

sha256:2fabc849c722ab81f35ea8779579dfbc21cce5a227807263f2a2ed64ad376563

Manifest digest:

sha256:49234167cd0ce33991ed7e69b28dfaea978aae784bd6d3f1a6f4dc029698d3c0

Size

4.31 MB

Last pushed

10 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:0fff2a915c6e81d070ff12d7974fdce1738438b6a3a9c3479dd77fb59ee15eae
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:d083e3a1570993560d361645a99432cf971bfa508682077b4421baee3636c8cd
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:f31b4226c90cf095292e2048385ca4cdc20f3cfaa8caf79b21ba3bc604768c60
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:6f9400233cbef6fd4dbaadce6acb5dd67eb32cf3c3125413643fc4b903459a69
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:4e7d7b53f1534e17779c341c4d226ae34d065ffb8ccbbb8d9671b0b1ad89ea16
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:59ed4809a2100a85feec236274d6f6bc53743a18a26acc931be14e882e3a3491
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:51dfab8ba4ddb7918377a644c9dc44b824cd00af4000859cdd4ced4f5a85ee7e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:1c05c013e32c107ce11e8ffd7520248bdcdda62ec494bc1633a3a5c813fe01f1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:4c0647a9dc5f014a5ce3d1f9666d22639f1247d931e9b6e45efcf97ea42788e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:257ce970996d0591ec74f5a49f0ccb79944831e63f552165b59105c96ed0b175
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:877a6a342cdec4eb4bea4fcbf898141b2acbd3584f0e4363db753cd37d65c78e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:9a99b31fca83bc2e64fe8ef8d26bb640d15be51603b2243199400742ec01c64b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:5cd022cade3c6ff182207947a2a81caa5b2a70f051ca714979d570cd12340d7a
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:b6ccfca8c39ee9d96c67b8b6b4406c7a90578ac4e5f463ebd102f2e608d40545