Sign inSign up
Prometheus

dhi.io/prometheus

Prometheus 3.5.x LTS

CIS
linux/amd64
debian 13
Tags:

3, 3-debian, 3-debian13, 3.5, 3.5-debian, 3.5-debian13, 3.5.5, 3.5.5-debian, 3.5.5-debian13

Index digest:

sha256:6d02603253a5e7d404c9f8db7227c0b2eed137cc6079aaebd42e8c91cac92e80

Manifest digest:

sha256:9e5c2dfe803f91510a9f02a1aec950feae551f569b29c285111e4fbdc3fee629

Size

55.95 MB

Last pushed

6 hours ago

Vulnerabilities

2
8
0
0
3

Support

Ends Jul 2026

Request ELS⁠

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/prometheus:3

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/prometheus:3 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/prometheus@sha256:de8dd46faa4b32940ddb72438bec8244e39fbae901a121a8d3b75e54200c0358
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/prometheus@sha256:ec5b03106e3c3ee49e2c48bad2fab26b3348cd9900e955ea6a4fc19297b9ddc5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/prometheus@sha256:daa3d1dc485d7f0802d9b152615b4f6b18063e4dff4b7ea7c61056a24517704d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/prometheus@sha256:2f05793ac6639ab167cb23ca66679f14d648da1761ef03dec1a4278e7a0a754c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/prometheus@sha256:16b6c1cd67f7e7dd01e1478dc8744a9e3282bf01cafbe6e1d93e7803531b7ab6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/prometheus@sha256:a56586906c3d7a34720a0e6fbf1e5f3fa06e1f4fbf9861db9ea4106b8b3329ef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/prometheus@sha256:16a7aa71ee86d7a882a087a2c78df12f5fdfbe2df164caae4cb034d11b26e79a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/prometheus@sha256:dde0122c027f5bfc36c23613c04c16349128e4cda269be2fa19d0c6af4723ddc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/prometheus@sha256:5b8e74f94695bf59d7a755679a569635a4a9cdb360da73d7e487917a1e93c9c2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/prometheus@sha256:6324542b8b8df2bb8433ce6889df0644c62b6ca882b8c5b5c4e24428e91e1383
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/prometheus@sha256:6acf4e69ad3b5b7d292cbb7e034469542a5a5f912d8b82a21276d92dfabe844b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/prometheus@sha256:abca15aa586a110329f4d36288f2bb1348e6da7aaba4f2f5399eb850afcded6e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/prometheus@sha256:a16107d9048d965acad3ecae634adf946f7ee449667187fd34d8bebaecb162a0
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/prometheus@sha256:4bdcbcc6d778dc87d4e18ccf7393f5320c7efd298897c8fa0a4be1b2c8d2f5d4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/prometheus@sha256:ebfa58b3e11c32facc4dd57c8e82de62635f4e48fae7d0bfa1c7164e9654f237