dhi.io/prometheus
3.15-debian-fips, 3.15-debian13-fips, 3.15-fips, 3.15.0-debian-fips, 3.15.0-debian13-fips, 3.15.0-fips
sha256:0c2eac0b9b8c901d2104da55c14ab2e97c19d407b8d17f725b0e0ef6e04b673a
Manifest digest:sha256:df39328bd5b9812d8e5314f3c02cff86e52642b4a8002b763d44e25e83cdb0fe
Size
59.42 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/prometheus:3.15-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/prometheus:3.15-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/prometheus@sha256:424fcc8690d6e5df6812cdc7d0ba6e1c224b941606d19a81000c02eed31da8d0 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/prometheus@sha256:2b1a4465d4b2b206c8b53202a48199a67f0c1f92f9e3cb65dedf9ab3833d39d5 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/prometheus@sha256:03abf65d355bd2bf05f2045b198e4ac4476a39d9c41b2f9d03f30d890af4c70f |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/prometheus@sha256:5a0a4b2240c9241105038a81f26b36285fc7975e4b9f1681c69dc8af4a03b6b2 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/prometheus@sha256:3314ca7f3621a13823f397486fd72d31a7947aa3c0bc4644494770912c918c15 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/prometheus@sha256:1c0d3ce91769cbd0b22e807ade1de51fdb6d3768b4797cac54149e7067f4fd4e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/prometheus@sha256:28a37334b2083fefa653cfd274afdf15cef08d317628025980ee48ea083672ab |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/prometheus@sha256:cca88b8084fbf702b1372ef27e809b0f16f96ac189f2b922dcff9598905b6ede |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/prometheus@sha256:7af9078799928595d3e8956b61d096d58d06d813a564f1142cd460ebd5ab6b41 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/prometheus@sha256:594327d7c1c9976b237002d19cb19ac41d59d4e03a321a532a4856841bb5619d |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/prometheus@sha256:44e2666c4ea07be9c8176d136034ee8a4d767ef0a9a914128a4e4e96ec1115d5 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/prometheus@sha256:84d0b7b9f9b3d84aa7ae8cc7e45761482601055ef9bb9097945cda2952c2948c |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/prometheus@sha256:3f78e73eb23a3435f697ab187fb05ce6ef2e4fca6b78eda82a8977ada4f78b1d |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/prometheus@sha256:e0832dc2df314a07d80a4b1d314f8e853c35e065c2028d790f11a95398ae3ad9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/prometheus@sha256:de522c809e030df7f305313408ffabe7336c0f598815cb38d1c273677184f216 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/prometheus@sha256:062e2306fd5803afc4b984fea93ff4b0f637d3aa7d8dd315741bf4aa2201f9c2 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/prometheus@sha256:3e614413f70f4cbf8ab9d3a8b017dcd560b50a2b174d27920dc7b92b6a1b4934 |