Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.19.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.19-debian-fips, 1.19-debian13-fips, 1.19-fips, 1.19.3-debian-fips, 1.19.3-debian13-fips, 1.19.3-fips

Index digest:

sha256:e88c89e8d5d92def157efc8ef5656a3543c7198e4c8dc3eb83168a88a4d9e9a5

Manifest digest:

sha256:e34ad7f7f276115a730e0adaa9aedff6499a72a97809170423ad3e1e83a1f8b5

Size

58.02 MB

Last pushed

9 hours ago

Vulnerabilities

0
0
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.19-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.19-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:1a745aa6931470fa9032ee680335b40ae696711c09fccf439bc562d92bedb769
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:0d5f5481ecb0a211c60aa75cd755ccb5e47138363945c99c8867cbbaecc1afe3
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:8e1ff960e11f4a265511e225a5d492067b2665e0b56e9ad54ca08008eb9dcab4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:40924e65da0e71b57bf8bf1834108056c1202e05124baa3878f8540f39f6e2e4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:e6505fc1eb1c26fac6f32694dd1c53670dea9113a8b841780283216b3b2ad985
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:03cb020bfdcda760da4da78e0554054d8224a90fe951d3bb2b32ee9083f4b184
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:b59b131db6b70cd0849f2948d5b745b65c82f233c9b01f3cbc2976363e3d1299
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:c1a4ab1405fe9b9b4ee1d8608994a481005633db6bb990950e78a9bfac037cf5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:13d456845a0e05d4ce8272b2abffa76d13ae58511f4022357134a4bcd3158f9a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:01bd03f632d6f4fc902627f6deac3610a59c47b7407573f4f42427f9135dd719
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:2afd10d1a6cacdf065ca80c0f421df9d2dbc67a1192e4020a9320162064c1d48
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:ab12a0fa6a8f88df05c7f58ed74ea2bb287c4eefac6072dd2f3d6c9d625ce6dd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:376397835f97bb9a091bb6fb5c7d8797c12e5ea4bf9fc4496a8c1e8991993159
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:e8c34136d410114f43ef9e3a839241f38b0bf66277704a9fc2ec2a891694b0dc
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:6cbce097683bc5506ebfdc436e3720574da96cc0457b34087ef6a1a9188d9db8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:7b61659f62a9c1fb0012623ef2ca695819b1480adc54b836546473932d4b1929
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:673a1382126a7e1606fbde8058b26f2b0008773f6c511fad74df6d09b4358e74