dhi.io/nginx
1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev
sha256:ddde0429ca7f8af08be95924b0278d8305f2474a64297d4464e5ffcd465e7be7
Manifest digest:sha256:87208b02a9505c5e7fc5a436a3c1001591fe1a9edcf99a1fb07dba80e665e4dc
Size
25.66 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nginx:1.30-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nginx:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nginx@sha256:159d7161429bf4f52995760dab9b43222947b019c85e3b408f987683aa42370b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nginx@sha256:1fe7549fdfb8002e6e1ceaf15056da18b451c82c208eb71056113a3bda34ce77 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/nginx@sha256:5b8767d5d7f2646978444b1d5b65d4878a96ddc7793cd1f8e529d0207e6282a8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nginx@sha256:c2f6621546344e06ad68565d305bfd6701d4627524c7d7e07c58d835ce0934d0 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/nginx@sha256:4251380a2005aae90891555dc6d4ff40b23a1a2cc895028f5d735ea9b527b92f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nginx@sha256:3f46400f42e99ff7befe0f3cf5d1968ad253cc1707244eede981afffd71b6cb3 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/nginx@sha256:53d062b86d1e64e902a1f1c29c3d770c6363012343528591ab4ced153545f49a |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nginx@sha256:65d9a3e7521db67acf837715d01ab21d268a4b912e820a46ad93a2217d0f10fd |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nginx@sha256:073a251846837d2374b781abfb0263f340f0419bf948e74fa9ed1e08b191b5cc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nginx@sha256:ec4726a226a2db41532fad59d43d5b325916ddda92a853456b73bb139f6fd4b5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nginx@sha256:3df3d22dd8ee78617e3b7e1cf46be7e7c6d1a858bb29402e08b81e45a64f305d |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nginx@sha256:ed676f2d1c31ebad883c7349738a8c12e8b28fcf56c843bfb4f0660ec1659c37 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nginx@sha256:517580655bf68504767ccfd015db02a7c8cfb264a2ac7fef913bcf54a464253b |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nginx@sha256:e2b6ae44933caa1e730d88fc50862a5b1ec274727b522dcb76340f384529a5a7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nginx@sha256:e029790c6de0ae41182e2a18aa733ac2d43789f9e10c6f8b620a39f7ebdb95f9 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/nginx@sha256:2ae265e2bff07c1038df49559b4ea0413d6dab3ddaefc9c22b051c0ad0891815 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nginx@sha256:60e3e36b45f16cb9c2e4bdf652ff0bacc180a131e71e64e2d0baca8f09bce0b0 |