dhi.io/pyroscope
1.20-debian-fips, 1.20-debian13-fips, 1.20-fips, 1.20.4-debian-fips, 1.20.4-debian13-fips, 1.20.4-fips
sha256:11a4bbd8fa1b2f9dd5c756f75377395b686187ecd053b4f62a72b28885ce0bd9
Manifest digest:sha256:2c810590f103fc30ac91c6f8e1454c0d0cbb895ef20ea57ce33a60be8e2d8780
Size
59.27 MB
Last pushed
1 day ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pyroscope:1.20-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pyroscope:1.20-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pyroscope@sha256:e0eb4a7c4c63da01f8c10051cc1986e4259cd534ab882038fd66b28879bd3de9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pyroscope@sha256:9af4504530b140b6fa917769b03fdf56b2b5f474de2a657b58ca62836421ccb7 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pyroscope@sha256:0ef161c0b8161c5a0dc7acf6d942768e76c69999a8b558dcd4719f872b585c8d |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pyroscope@sha256:613ac12405a5c5ce99d003ab70ad54d47e72b74a221ed4a9ebbb6d6798d56dc9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pyroscope@sha256:8fb43c928c025437f5ff0b16b069a580e8e4b00ab0d23c56a4e00103d0314c2f |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pyroscope@sha256:ef054f960fd6f0452ffcd674d9abe936375f26e1c0b5f9505b9a1a565148a0dd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pyroscope@sha256:4114edd4586b118a4cc036927027bf8d65193ee87464ba707a809a2434e65570 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pyroscope@sha256:57bafab77b357b31525d42eb2d2e318137e6c798944c7cd0fa882ad741f88129 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pyroscope@sha256:57a8cf12a39be739f4947289338bc680c2e6364105d09c19954767fa7ab4b85e |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pyroscope@sha256:8932d618309335386522c2e665c06805231f6fafe89e2ac1a7f5c281e58ca609 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pyroscope@sha256:826b84ca9cbd23fc411621be61b62bac39c3687dd47ab7d43fc9bfadd5b2f27e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pyroscope@sha256:1fef01489f5bc9af114cfec98387dc0cb82be48235a5480b0dbe9e6ce3260ba2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pyroscope@sha256:88cd53ef8059de8bf871ac3dc049b49cceac248389b01ccbb8b7e3354cd29f22 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pyroscope@sha256:7af4f3879bb920d5773de1b3f0814f2e4156f0d1912d0952047fdf78a4d41a83 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pyroscope@sha256:9fdfb9dc4d9a57b4df9d083064d0f1227a98035fc8d01f0982f4f2672bc2a05f |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pyroscope@sha256:83585793831c988c1fe1c40d93cfc06534ff3931e6708d4ac58377ff9cdfff43 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pyroscope@sha256:36dc70bdd5c1794c4947b152d454f94e3249cb193224d0e03dff3cac8de45bbb |