Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:aa86d833925f69a8b36c97d3767f26556fe9ee9073c10725c04b5d592b6dd4dc

Manifest digest:

sha256:2afc2e31fafe086e7b117689bc576d607ea515086a8b15d78f1e23ff4a0af485

Size

24.90 MB

Last pushed

14 hours ago

Vulnerabilities

0
1
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:6ef1ec4ef5505c8111aa0fa84c00316c6f0c8a12f959cc402c39b229e1473684
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:f01caec0613eb088cb097f3b6372b7f23f3b8757360e09861b927c9cb7bef2d0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:4957181d32ea98639844649a92c22f0cd58993d68ee9854e06a67819272753a7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:d108e1be4cc758ec6073b5946e794c25f941b458ed5884b5059897d0bb66b8ac
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:6363d5ca0e904660c2efa35ad9b462c65fe558a62d02f8f9b2e7809aea27d52f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:7c74381ae88aa70668848d49d789448f8eccc08753c2011f95ef18d5a5b35c91
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:663d0bb862bfc986f674ae00f6ddd4797a9555a28f8501e6aed0020d6a3597ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:e03f255317b1e1db08671a73b650d3640e03f53bc296f6dd6efafef7dadfbc15
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:fcc3fe7ceea7e29b837273eecf5e7262dd6a22e3a60e1ab96d6aeb9e5820e111
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:b2cf83773a8b6f4567da52b45d3b0b2c4776a95c4f657e0972cd21144a7ce98f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:d0af9fb65c52490a9ae924e7d3c8661d0366747e8595b0103532582f06262542
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:4ba42080c7e7c8759251e87b1e15694474e1897f03006f645756af37a4c30bb5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:c86c8d097055c63039dad38b38c42c8534cdeebddb476a41338df0d8ee288061
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:87206fb26fb92052d32a6410e91263148ac5b81b548d0f4dc087f20d6cc6c23f
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:de89101349be5138838de88c69c7c9265ce7a3a46e7a7774313c5fcfb9a6741c