Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev

Index digest:

sha256:bda46d991333adbee08a6ca9fab40c3b000c5d829e95bdf6024c28ac24cd9443

Manifest digest:

sha256:7a0a613b8dc8eb691b6d5d730dbb5ca69bc027883351a9f1196072b5830d55a1

Size

25.67 MB

Last pushed

22 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:3c2519e41f6485fd4fc56df68b9625cc5f88ce7ce2592e4ff41d353f456008cf
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:14282fd4373466625c44fc82fc96a56802b358dc05dcef53a6a5b832c43218be
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:04d5f707bd6bc8b3b162105abc73b32f3c05d8811e482bc51b0849077457359e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:1b1f22856962a3216b499da52fc8eed0c54912c79968ce9f0b8576b5650b349d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:9313a06db230b63ab5c7c1cf4044181d1399142c9982614a1d32d94c6c17e974
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:01b5f48292d2b4ca437cb72f177528dbc8bd5cec9acdff26356d52f57879a078
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:8959bb5111fbd9b994dd81592851cf40713caf6e8b1756b10534a1dd02e54c88
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:31399e08299d7baddbd2987b6f80757c467b79b8a8e5dc42cd274e67cec10681
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:f677cac529e9f77bb67c888fa721b7450864e1a4f752ad7e65aa0cf2e2fbe493
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:b83a6854a966d92677065d6194143c16e989263f9263538757f45bd7c9d4a199
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:2f0808077f47202f3b290e08aec0fa4fdbb19d55f086ca037dd599e52a9ce2c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:841ef80bf8b3d98f3a91a9af3cbebcbc4e3fa86c14197c92f1c5ea7cb013d810
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:8b0679fa7980555744a77962fe7e4fd0cf6c052ef2ace3a7cbf2903d7de5f38f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:ac17c49505c0a897a812e3fc119ec0e6816cb92a68e4bd4c221ee325a28c4b00
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:dce838dedf5cebba547843947cb29caf21a86c665af30b9f032a84bd6cd5bdbe
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:04d7e1418c246a46c16da871b416fbdc1703ae50a457b55bf7f81ba39722879d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:5623038004444f64baa0ba210cc92772d7116a1d21f264710f781f8241a974b7