Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.11-alpine-fips, 1.11-alpine3.24-fips, 1.11.3-alpine-fips, 1.11.3-alpine3.24-fips

Index digest:

sha256:865b4a14fefa3f012c28591e416e86dbd97a272932d50f078d4a6fd8ddb42fb5

Manifest digest:

sha256:8267913107ebe6988ee6d6f847f24f21f5d7e7ca87e1e4c404afb863d46a3e85

Size

10.03 MB

Last pushed

6 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:2d4a97f3022a4464c66a6ff2f77b66b8459f8c34d9dacc711ee062333529146b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:e82d89fbfd63dab73df9e38f27cb8123d86eed8b362b904f14719a57b08f9754
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pushgateway@sha256:977068f4f3dd955c56e402023deeccc6be5081ff63725a475b0a5d3682efb2c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:f1469a4f0f71e42d99243c75c2624bf02a4256316004db7c619f4af375ccd902
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pushgateway@sha256:02ecdef155a8f238fac3e590df346261bd8ed4b7f226b7ae78e6cbde99f9d81e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:bef24f02d945ad88cbb6ad9e8da64c7cfbae421a448d9191b109f731f743f3f5
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:c244a08c7c901892d153f827c7d45316be36b83adf4493a403516941ada3d3b2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:d26689cbbb9354827d48038a40e8bb4dd92ffec0561a17d90ecd6f31a1ad6e17
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:d540d10977b686039f299ffde550ea1e1cc7734857c67a3fe7f0a5775fe4ca90
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:781cbdfaa2fb480ad170cbdd70c245b08591c2d3d6d22eac94d5a3ebeb10f254
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:7c9d1af3ea73043b1233870836e71bdc3dc4ce7ccbdcf1b4ebad52b237f4cc3e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:38d6504cef6dc807f4033217210cf43063a0e6c37efc3705756341ff7a6bccbe
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:2e9490ead621fa99430b5a9f273ccc261cc1bbaf01f3f9278c58a03bbb01c446
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:0d6164322ccdb6bc304989fc339f88310dcd9b9f4047298f66b803a039f371b9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:03c0286afe6a21185ca74dfd7d195f5986e4969a10b960c2bc2c06911d24abc8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:c658e155849bb836c2c153ae1e0a0e33217366f838804ba689b06c991dc2db9c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:8d4ebf71bbfe579bd00e2324464c41a29ab2885eda273e1439f76c6c734ba2d1