dhi.io/pushgateway
1-debian-fips-dev, 1-debian13-fips-dev, 1-fips-dev, 1.11-debian-fips-dev, 1.11-debian13-fips-dev, 1.11-fips-dev, 1.11.3-debian-fips-dev, 1.11.3-debian13-fips-dev, 1.11.3-fips-dev
sha256:6ed0a991e19096f2618ceacfebd753cb0e0b4bcc54af1ff14f65426f4378dc63
Manifest digest:sha256:f9c0efb804b412b5ffe5c3fa78b19dd751f7c6e09fd173ca5ff6aec57c69dc93
Size
34.66 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:6507838b0b67f108ac1c7c35e0e5cd99710b6e6b630e583292f2d2ac27860290 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:94d51c0cece75207570467c441d6ab005668f1b535442a3d5bd584d8c4c475c8 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:9729f60de22c137776e464e56d21aa980930ff91ea69130acb14ea4349c7ee9b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:419797ab040ac6c45c837cc24c8c48aeb0ed1790e8c5503d5bdee146ddd1e063 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:38d245aed8f99621e74d9b3225b63ae728560ae47d360842d50e41db7be60e5e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:09b588d4c416397b9f881eb7c75fd3c8e4a141f05a78cd755fb4ef507d91567d |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:0e3bf311fac251c2a843c30d2c5fbd0796fdc7f489d0e3a49d5838fcb010acd5 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:33f5bbb89145dd0561b5e773438c0dcd582c5a24defbe1766e4089be6383706a |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:839df52be9377538cca5ea0b39ccb107edea88a3c4fe0c6ce0d3b846b42cb90d |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:348fbdbfaca53316ab89b54d3dbf9d1d312adfe502e35c246715d7b55f345399 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:edfed1d484649e85ff1a7b016bb69b53657948039f9f92829a2be30a3d689487 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:6d8c3ad0c504ef0b3775951a04f971e75b67754d40ab41492472319e08550074 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:c8a651e10066d696ad47d3e6e44442be5775f044752d23b866bf83765f088454 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:1d5b5557ddd6af7827442880a335d358995ade1512e897556ad670ade705d11e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:16394f1eeee1bc44a4e8a83b237391f2acab7212cf90d765758fea06deb98da7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:ce1ebd04b9cbd8f8e41a57aa1e572d467934cf82c5be780b90c569532cad66f0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:8eed4e3c03495da7fde7198a45c81db60c80bdf958676dcf6b5406df728ab25f |