dhi.io/pushgateway
1-debian-fips, 1-debian13-fips, 1-fips, 1.11-debian-fips, 1.11-debian13-fips, 1.11-fips, 1.11.3-debian-fips, 1.11.3-debian13-fips, 1.11.3-fips
sha256:7ac4171af489998128f87c1fc0a8f8e0af291b39d4fccf9aacf26ea1d994eb44
Manifest digest:sha256:6ae0a8dbfcf2468fa05f22eaf9ad6b944baedb1a261d1a2697b713573aeb8a72
Size
15.12 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:34d9ce46129ce4055ab25f72c92e62103353222cbccbf257ecce3ad0ea571b44 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:89ac1945f7ecde83ad973b49fe2a2976791a5d69c89cbc9625ebbecd3c06746f |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:1802557af125526a94db626c87b2b4dd445f25910baa0d1a94db398b8ae22ca8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:c0e6a9afd98d4848a764d915e5250f6ffb61a3cb6c338d1ec6b616d65c6b18c3 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:13be6fca6da3d87bc173f5a6a47145d6e76a7db8b6528daed0a0f03d451bee65 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:dc184e7744c87914cc3050fe80d9e1b1d29b8e80f3abeb8220afe047a69b133b |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:5ef9ed7016730e37658d84e81aea581fa69268b8401f3e1e11771a953c1652f7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:cb94f38ca68088d8d49eb986520dd414eeb56c2408bfb2f63110f0d8f2a122a5 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:ace7adffd9f99919b131fcad69154a965962b0cde7b8acab522d01ccbde38f32 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:8547b4549d8dadb488b023a88c642d2dfd12c17099d10085de8894a92e5641df |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:36bf0ff8d09ad9d418b678e9e7a556b022f3ff3a8038acaabace7dc775c64cd3 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:4e8689de5cdc061b4fa3b7f23341c400913e893848410a98efa5e105b9db2ccb |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:18e0e6a3f877cc387442a3da7703d54b098edd254fb06435cbdd21521e6e893e |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:98f1e4d06ea51e235cd5ebb4384331db3981fc77fee62cf2bbd28009fe67c8c2 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:dffaa4daef5d65a5387165c471db4e5081cde85c2f4aaeb5e8a8ac91984b5c93 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:2ba506778177c95040ca8c388adeb131fe74f1f2f9e5cc79fbf3562fb23a3d5f |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:6577ac62bf9dfce8a3b48eb8622787b809279d3b1b979490703f02235b4a3c3f |