Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev

Index digest:

sha256:ddde0429ca7f8af08be95924b0278d8305f2474a64297d4464e5ffcd465e7be7

Manifest digest:

sha256:87208b02a9505c5e7fc5a436a3c1001591fe1a9edcf99a1fb07dba80e665e4dc

Size

25.66 MB

Last pushed

2 days ago

Vulnerabilities

0
2
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:159d7161429bf4f52995760dab9b43222947b019c85e3b408f987683aa42370b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:1fe7549fdfb8002e6e1ceaf15056da18b451c82c208eb71056113a3bda34ce77
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:5b8767d5d7f2646978444b1d5b65d4878a96ddc7793cd1f8e529d0207e6282a8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:c2f6621546344e06ad68565d305bfd6701d4627524c7d7e07c58d835ce0934d0
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:4251380a2005aae90891555dc6d4ff40b23a1a2cc895028f5d735ea9b527b92f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:3f46400f42e99ff7befe0f3cf5d1968ad253cc1707244eede981afffd71b6cb3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:53d062b86d1e64e902a1f1c29c3d770c6363012343528591ab4ced153545f49a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:65d9a3e7521db67acf837715d01ab21d268a4b912e820a46ad93a2217d0f10fd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:073a251846837d2374b781abfb0263f340f0419bf948e74fa9ed1e08b191b5cc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:ec4726a226a2db41532fad59d43d5b325916ddda92a853456b73bb139f6fd4b5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:3df3d22dd8ee78617e3b7e1cf46be7e7c6d1a858bb29402e08b81e45a64f305d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:ed676f2d1c31ebad883c7349738a8c12e8b28fcf56c843bfb4f0660ec1659c37
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:517580655bf68504767ccfd015db02a7c8cfb264a2ac7fef913bcf54a464253b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:e2b6ae44933caa1e730d88fc50862a5b1ec274727b522dcb76340f384529a5a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:e029790c6de0ae41182e2a18aa733ac2d43789f9e10c6f8b620a39f7ebdb95f9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:2ae265e2bff07c1038df49559b4ea0413d6dab3ddaefc9c22b051c0ad0891815
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:60e3e36b45f16cb9c2e4bdf652ff0bacc180a131e71e64e2d0baca8f09bce0b0