Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.19.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.19-debian-dev, 1.19-debian13-dev, 1.19-dev, 1.19.3-debian-dev, 1.19.3-debian13-dev, 1.19.3-dev

Index digest:

sha256:142dd50b3b99529b0d08fd2788bd05f7a0d962d8473938a51506e9a9d1ddd906

Manifest digest:

sha256:66b32dcbd23b3a9725e39fa90aecf3f4c17e2e4c38b266f9ef978bd5a88f0435

Size

118.03 MB

Last pushed

14 hours ago

Vulnerabilities

0
2
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:73cfc7d3fdd11e820711b0ab5e928e987f9220a8410c59912f3c883f2364abe6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:9e59bc0bda0782af692a86c97de5ae0f4f57b6c8645f4e99f7e82f5dbcb6a9e2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:b8dfa0004ace59e629c6039f26c85e2ead3272c5795f6d893ccd8091d8de6067
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:a60ebec02d627c4b5a96aaf956f3682ec9879f02f35f92614e928bef4b45e08c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:8ef1c5aef32a610324e849a07f2d10cd6c3401be71bee1570bf12963be099b78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:23aabcc23a534a93db93244a86e9dc4ecfb6130f6bc1f3d480d6a5e8ddecfca8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:99531d029e1b234a716c965ec265e3640a860bcb640a686a6a516562a6ea961f
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:7a2be2a48dd99bc85e8923bf68af0edea5e3fbfcc378615cc3fb2c6d788179e6
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:d93d271dc55c7a34fb2bf8ea3ba7c01f2830d4d282e82d850b6053a203bc67ee
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:6e42d53005f70aad8c6df358a4a0fa8ea6ca32b4092b62c5d22d0584efd6f884
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:267396e397bc038754f6fad17d32e3c3af01b6992d91cc80cdff13d057500b16
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:fed43affa28c8d43841cb02cb3319f66c95e3566bdef7d251eb8dda3f440efb6
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:634746db2a668f150018f9c5d91f0607560be56a27a627ed8627a828787e2cc1
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:7fca8584bd559f2e5011ab18dde8b90f6a5b4f3bd46770e1634c8d5fb0eb676e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:b2396dc18c39c56aaf54005e0342791c9eb33d2486614462553f93237d3a89e2