Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/arm64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.11-alpine3.23-fips-dev, 1.11.3-alpine3.23-fips-dev

Index digest:

sha256:ff774808ae8cfc89effc3d85955cec61ec9855b68c9c268a2ee3518eefaa3e6c

Manifest digest:

sha256:76c9c16f113114d1a4d9403b1bd67f7ebaa72ca948901b6a4c3bb0dfa65d4901

Size

14.77 MB

Last pushed

14 hours ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:99966bc7e7965dfb83fa1a4f27e161996daa7f6a32f258e209eff7b3ebd473f6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:41a23b8dbd0c7515cf1c3bc773798363cca1ea3512919f65efb4b161b8eddb34
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pushgateway@sha256:913d3c094626a711db31f7a3f1de1474d2784da69315b9546e118563435bf536
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:d0686dfc7b9421dbc55fc57c36126dcef22dd96d7ab587980d48a4dbef31d6e3
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pushgateway@sha256:8acd6dcd669b50ddc6f4612bd9d21fbe7ddfa750b1a45c4bd9ace862a4bf7082
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:01a255175ff54530dcde30dc5462e9050cebd56bb8e27ea9cfb308e7414591dd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:5a1b9584fdf48e007efab588723e453aea33f4072f38d249db914b47e605f217
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:a23c8b7e3b5cf703319dd243f3719d3f6e0cbc2fb6ac70b79517591b1e4b3956
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:42c8b55467f33e5ad61b576115fbda279eb40102913083cf197a942413060f08
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:60ca4d67f21bcdebbd2c6369566c4fb6a29b6f8b6a3e3bfd367b4a84c677dacb
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:a08cf940aeac9307ec6221988b93601c8eb36434dadc3595d6f3476b9b60ce93
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:97f2f365b13bc40f88c99f41a3d7116d99d5e71e1c297bca83c7c7aadf873100
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:12878a7787daee08f1b95c59fc28e3f39c7b3c874e21bb2c8ecd0482c939f3e4
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:5d386bb3382201f22df30ed77dda54576b5ee8fff3d1d6c45e95e48e4d238792
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:69744f14226cee7ad8ab08a93781c70f756c9bd0d19b7bba6165b137d9de373b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:0258d4edd9bd5d42443d51905baca7bfb959d9a1033f67fa97f2b517c0db7905
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:ddceffcf7579c9cb52fb06158693920a44be45234ea337c5b0bf0c75022b1402