Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev

Index digest:

sha256:19cd85fb0fe5a4c4e4a57c2600992f99f4d4aeace10a269caf695e7847df2a7d

Manifest digest:

sha256:a707cf0bedffae25778c7beeda6bee5a65b00452e007da39a1dd2a3aadee925c

Size

25.66 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:b4a5f27da224ff6708ac2529e08428eab2132341c54a6c2894d5b3d84dacd705
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:bd32ff97f276496562d74f6f183f2dc6324b7466dacbdd75355caf27ef6b4c68
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:2066023a0ec1cfea13d0779154331175f165f6cf1156859801eb1514dd5a0de6
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:42fa48d2af485097fe9bb2004b87dcee76336dee3783cd50fa0bb43631579e9c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:8f95285f12993b619d8ba5b475ec1131b823da4890e65719dc4fd5aa71d1b41f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:ef884e736a6512bd61a8b0dfab22e18ad30d40cf3e5748ab081d6f84d1d5b9dc
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:15dcbee6c44a6bc04671712fffd823e91264fdedaefa71bd1c43f5a646fc4ce7
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:31646b5ba69cee89925f9938b9013e97958572f14237ab1712426dd558cd5995
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:7072e57751e9c11b568c605373d43de09b97768ccb035784aa93e8dac7991364
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:a692036095570ab90627e559ac24f93cae33ef917e308a5ea9ec1f774d07a5af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:889192a535637efe1e016620bc940ae07a5c4088001369dd394c9366277eb796
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:7625b210139271253d55751066bd82ce9d1c2978bf81d673b05a11fcaefdb2ec
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:d51b49ba4b45e48d3cdc3863df1400c1983aeaed3e8e8e0a5508924a89f5cd30
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:731d06db427d568a9adacb73d78ff7fc10c38788c4075e52629b050fee60f33c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:0ff65e313a2c82e620d7cbbd543f59b2681eb7399d6f83c3edba9dfc7fd7aaa0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:fafe7f016a886ce836b58e6d0b9a8b117e351728cb37deb073c993eff43cacbe
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:b57e2477bf03c35093d03b3591ad09ba56efd56e43eddf7b4076ba6442addd0d