dhi.io/pushgateway
1-alpine-fips, 1-alpine3.24-fips, 1.11-alpine-fips, 1.11-alpine3.24-fips, 1.11.3-alpine-fips, 1.11.3-alpine3.24-fips
sha256:865b4a14fefa3f012c28591e416e86dbd97a272932d50f078d4a6fd8ddb42fb5
Manifest digest:sha256:8267913107ebe6988ee6d6f847f24f21f5d7e7ca87e1e4c404afb863d46a3e85
Size
10.03 MB
Last pushed
6 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:2d4a97f3022a4464c66a6ff2f77b66b8459f8c34d9dacc711ee062333529146b |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:e82d89fbfd63dab73df9e38f27cb8123d86eed8b362b904f14719a57b08f9754 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:977068f4f3dd955c56e402023deeccc6be5081ff63725a475b0a5d3682efb2c5 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:f1469a4f0f71e42d99243c75c2624bf02a4256316004db7c619f4af375ccd902 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:02ecdef155a8f238fac3e590df346261bd8ed4b7f226b7ae78e6cbde99f9d81e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:bef24f02d945ad88cbb6ad9e8da64c7cfbae421a448d9191b109f731f743f3f5 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:c244a08c7c901892d153f827c7d45316be36b83adf4493a403516941ada3d3b2 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:d26689cbbb9354827d48038a40e8bb4dd92ffec0561a17d90ecd6f31a1ad6e17 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:d540d10977b686039f299ffde550ea1e1cc7734857c67a3fe7f0a5775fe4ca90 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:781cbdfaa2fb480ad170cbdd70c245b08591c2d3d6d22eac94d5a3ebeb10f254 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:7c9d1af3ea73043b1233870836e71bdc3dc4ce7ccbdcf1b4ebad52b237f4cc3e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:38d6504cef6dc807f4033217210cf43063a0e6c37efc3705756341ff7a6bccbe |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:2e9490ead621fa99430b5a9f273ccc261cc1bbaf01f3f9278c58a03bbb01c446 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:0d6164322ccdb6bc304989fc339f88310dcd9b9f4047298f66b803a039f371b9 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:03c0286afe6a21185ca74dfd7d195f5986e4969a10b960c2bc2c06911d24abc8 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:c658e155849bb836c2c153ae1e0a0e33217366f838804ba689b06c991dc2db9c |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:8d4ebf71bbfe579bd00e2324464c41a29ab2885eda273e1439f76c6c734ba2d1 |