Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (dev)

CIS
linux/amd64
alpine 3.24
Tags:

1.30-alpine-dev, 1.30-alpine3.24-dev, 1.30.5-alpine-dev, 1.30.5-alpine3.24-dev

Index digest:

sha256:e5576160d88771e7f0e8beaea227858838fa7e20ba3a7dc264326ee906ea2da4

Manifest digest:

sha256:b1243010e014fa17a6afb3131cfbdbf968f2f1ede47bd02b12af99a125b392c9

Size

4.30 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:4ca44349988e32cbdd4d28a7b97efe355caa709da2233d0b89d332e98cf261d8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:3be2e7f330236bb6b21509dafde6c3d526db6fe3a3dacf04c86194d6d5ea5e65
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:7e24cc8925d1d2cd3450421019bc9d9def1d1debe91ef2e2d4189faf57a74944
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:1183c4221c18adbffc800ab07acb54a9e5347289147874ac9ad49d33f7a1b77d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:9f44eff60cc5bc781a5d3a1879bed773e92226fdefc589b8e9c3ea43be4cfd06
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:1896fc812a2b547ce8af9cbadeb9fd140cbea2f6b74027a7bb29614508383cfc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:cedb297c6206e68a7149a5b84cfa3558b93920085709f7caf767f049bde1941d
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:214f697fcc8bf0c826fca0184e92939f3ec6aea84d7f9c25f201e8dd807498e7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:dbe1a9c2de08be088da0af99889282dbdd1123315749ce14bef29d335e470106
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:81ade9194aece7d329e1d32efde2b843750d41a8eb7abd9b0143bdc693b011a9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:699f027170242cdb744deee07ba111bf5f7afebf21c70403693812080f155fd4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:9ad429ea130fe0a4e7f14292329f96d0a3740f9bcd4b3c88c5e799638cab6ed3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:507ac3f5ceec880290d0776d9176cf74eee8e99276df02e7c4fce2449b0de714
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:d1ae280baa76f2ada8b8b165086dfc31ef3005d784330e89450a04ab564f41ff