dhi.io/pushgateway
1-alpine3.23-fips-dev, 1.11-alpine3.23-fips-dev, 1.11.3-alpine3.23-fips-dev
sha256:ff774808ae8cfc89effc3d85955cec61ec9855b68c9c268a2ee3518eefaa3e6c
Manifest digest:sha256:7b8f8b0dfa99928c367b9bff5555a0e868abb47432d111f3742f8b46757d000e
Size
15.30 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-alpine3.23-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:8c0d79a3d09e241e97bc7cc284f40e6a209095fe44b3f837951e094592d9cfa4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:91f276f193094f4b82910c4859dc68dc30a5930009cc0180385501c23c12ac11 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:de0985cbc3b865ce3799b9ecc31edf4fa5ea6c6cd45b5c7f787d271660411917 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:04a3bbe8b831186542d5e5f000ea8bc35bb34c81ad4ab0d6bba1770fb083de3e |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:36ab39379b1b7f2e1baa6a0bd7b5f3f32a65187d3cc94cc1bf68158fb9ede057 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:232b11a3a1be76d3c4002faf4a4b10496e00fd166109ffadf19b516ae6bde4f8 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:3a5648d13629266aa952f4e04aa4b8eeb2a329edf56312ea2dc12e981909f4e7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:a2645eeef475580c0de9a743804faaaa996b5d1b074b436243de1152b94ee9d6 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:fc91899f9f88a5ce35cddb1ea7f2ad266ace13f28f760015b982234fd59e8ffc |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:5c6406c97693cec9526cb3d345e7f530546a603d3e833772df1f1247ffa4909b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:619d7fa2b559c13577cfd7b416eb42d57ce556f8ca2deb3f158aecc499c41425 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:7cf51b1ce49cdfe8c8fb26997725657c8a6efe82793f708f0495443748fda51a |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:c33115c2fac175bf96e746675df902b9ccfa30db4d6f475751b305143a6aaeed |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:09c6e7f6494813c043fab0cb64f30460a6c34abddbedbcf8a51cb02f22f29d85 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:44b329f22752983f36e744639f2eaab20206a1edfd1a04a2f57115c25951ecc4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:e780c431b4379c32489dad75b29caa19ba253dfc88fd00d74fc09ba800c57e71 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:837ab78a4ae7e4b0f6276e52badefdbfc16655edab0bd43e7e865101dc97bbcc |