Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.16.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.16-debian-fips-dev, 1.16-debian13-fips-dev, 1.16-fips-dev, 1.16.2-debian-fips-dev, 1.16.2-debian13-fips-dev, 1.16.2-fips-dev

Index digest:

sha256:3ca9bf04d328a0e88a3f8245f978c0881915f327c64750aa4df344f59f52b94a

Manifest digest:

sha256:54f03e4e7eead1ab603104e833c8f135676df2d006813a93bbc264c5be01bd1b

Size

115.56 MB

Last pushed

2 days ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.16-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.16-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:b673bd1d96a5d95c7c13eba61fd63422e8092cd22d2c4ff928b61f0117b89af5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:8ff7ce39b70caaae4fcab3614a6898546f2797b0a100496da01250c05944837c
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:94108f223bdaf578dc6a2c77025fc9e39a0b4966686427a4a544f65f97b06364
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:bae875ba7f5ea28da7e7c410684bab726de26aacccc1a205811b2f93f2a458f9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:a8afe27ce1c1385e11c9cb29a73b511c99137e099ebcc04afb03641ccb459734
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:b0cd4c77638508af21385e0f6930fe94a3272f02e54bfcf69d150474244a1c5f
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:00178cade68a87dfddbe9065504bc9c02246405367cd504e43102a8a32b2b377
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:23aee9254356476e807e3ec3310754a73d908a8c440a25d1f890c1b6acd5d024
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:18ae0258369d2e8488e60576841bca2c86907873a0b2ef7d4e772722e420425f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:99b2e329a7957764bc2714c67dd70cf490a4d79fd789c0bf658ccfea522843f3
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:02593ad8fd7f984b959996f8c84faa4a26084bf68bdb674c8e9c78fca632edaa
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:213a7c170c55ad272caef580a11d210135910085f5051e2b36e65a1570720f8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:89eaa7cb1c332f98f464898137716a5d180d561312289c99910c9e657ca0397b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:09b34cb9300385d396f151d6500d7b2b6e656b4d40769517b2c7270c4b4ce699
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:1798feb046314e567975e58c7097fda25344b533c7c236859d7c9d0c3015988d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:df3c51db3e0f681c4d5968618ef1b5486f37a0577b95f44e6cb9653c86261af1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:55defa6fa04435a1191b134eaa350752a45caaeb441e69b778a6ccd3a161c54c