Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.18.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.18-debian-fips-dev, 1.18-debian13-fips-dev, 1.18-fips-dev, 1.18.2-debian-fips-dev, 1.18.2-debian13-fips-dev, 1.18.2-fips-dev

Index digest:

sha256:8bfb432e9bfe12a8e9ab8fdbda1dc26c1852a9d8fc581a9adb9af763cc1be191

Manifest digest:

sha256:e85d3cd69af7a17ffeed4e6e872b11f4d70549853353f77e9493056ffd3e4b80

Size

117.73 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.18-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.18-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:bf59649a64defe9dd28dad40a9928f1f099581b8707e9af2dbcc2b68e00aca2f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:c9398bcc5b9191d1794422dda682469406b9aabf2e4fcb9ebb2a556f34efdad0
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:32b60124e83e12ba02cff332999ca4a2c4130941a938789d4920590c68ff7a4b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:2fd6e8ba9ef8ca3f5712f5146f6d6802c98d5cc0018577f4a7df48aeda77d010
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:e34dc324845889717c9b0a90e8bf1dfebe357da4b69b59d655a5cd0229e3e27c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:cb8ab26e9cf816798132a4a7daae6c1ccfa6509aca4069d3fa7698ff28333e7c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:23157728f1a7736c518fd2b00625687da8008174b4fc9e166d9cec883c8b62a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:53b8b14fe6460675c8e6f86bc3c66a6e6273a3d6af167a5ed893ad77a240d0b6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:4bf8a84236ff634b4e00283a484f987d1f22b81eb1454d7c26d0174afc26e6dc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:65248fd75aeca61cabb3719b157afb019b88af114a38cafc9038935566f409ad
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:5582c5d05ace8f63d8cc252f37927a146be88f5b9de516f2b5b3a9eef07ef947
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:f8775f01b98e125fe229d43a3c566251c2f3feb842260bbf36b1231b1494ec7b
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:0aa24cf9acffabe5e72020663b5dfef168cd27de171a28c9c3aadbf7ff621a0c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:86f15686c41ae796e160abe15a573c077644c681170aafe65a84309271bc2222
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:70675f6a62c7fc72b5c9b319de7a53a9fc715078aa48344ca60bfc9e1aacd1bc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:3a1dd292d41c3f64bce4de4e3e8717bd0947189692e179819945b71b99f48dd2
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:988536dd44d21c066db6148381e4e2ad0013aed49339cf5324fb69a0998b00c8