Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips, 1.11-alpine3.23-fips, 1.11.3-alpine3.23-fips

Index digest:

sha256:a034bec2322ee555ab1a03fa8744f8cb7d09ed3eb75414de1152dc07d7d37904

Manifest digest:

sha256:d684d82afd383ae1d337176157e42e79db53a1c7f34f0f461b17092183138366

Size

10.02 MB

Last pushed

2 days ago

Vulnerabilities

2
8
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:b6214b1fbf4e262f49c13ea717f06beb32cb7c0374073381896f7354d0c57105
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:d163028db61c59ba9f112c5a44e50c8a96393cd714b25c607370b93a7a55254e
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pushgateway@sha256:7ea23af09dfd4364cc5d8b8148049efac829390a47d730260aff41d1b1d1e618
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:0a55bbf500e52fdcd2ca76e0a045824d9da6b7e411b2e80f2de0fbfa72ba2c21
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pushgateway@sha256:a8a78ca1d7139a1971b318408acb9738f8a952ca35cf12b862a1f7e97d4855d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:f2d3f471319ae214a197a584bc48df55c7e796647250b7179498cd81394b8f83
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:0c5f2f51e8d29e1ddb1610541522c4a90bfaf12514dc9c526118a0f7fe2b6bb9
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:b53c475718e197e791189e288cc0e2137baac5371a563f3e006aab718180cbc9
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:dbceee6197f35092fd8d0b766fa680b1c50accf028c7edf31a7a59dbbdea0c4f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:de200034fc386ac10c07bbc9cb796a4d12c45629e08ca730c65d82ca353b9628
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:6a604ec57969bfc0e2cab21a3ace361aef1bc9761d211d4104f39649d7e2ee74
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:7a194c3a050774fc8f9f3734bf0571bafdec0d6227e0184826f712098985c199
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:f0993080f95e4e62b3596fe8d0ec85a765133fdf8cf5da75153868e8741bd564
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:296cecf646c08952ad00ca45fad8c25081620498d0d2d8bbce0e6e65f86d53f6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:45c02f8968d01dca64764a7953b552237f21f15f18c2559aa2d9cc3b476b3e28
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:6c9c2b6e420b7f1d51f24b2fedd8ef8e24d315c878d73cdf3530f9eae3247ba5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:9aa64774b4e39fb5d6faaae99c5a26e45af583a430c06783c242d8f44b07a0d1