Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 2.3.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.3, 2.3-debian, 2.3-debian13, 2.3.1, 2.3.1-debian, 2.3.1-debian13

Index digest:

sha256:4716d3e2ef7f8efcbaeadd13494c437a7a8e72f8f18ec5f7594595d5d7f459f9

Manifest digest:

sha256:54f884b44cd758a285118116cf953e09cc20521d5a8f208154b496b749968365

Size

52.06 MB

Last pushed

5 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:bf085d06eda7e80b156bb1efcb8bfcb15541b23850e3b4370ed0ad4237d0a6c6
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:e8936e77ed5d050ff7f7e30f994569517c5ec66bede6579d55b66e3d15deda59
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:f2224a34d3819171bff74b561761b6f1fadb4c32250238a7c0c87f3539bd1685
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:cf044f2b6cf43610ae1c1f279781679e7143a6eafa00593fe4c2e0bc1fd39211
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:d76ddf3664bf44005821733c2d98242cbd6fd2383dd9d4f98e7a63c807975433
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:3bd70e0d9314a5e9114bf6105f484962590ec4381ad3825d9893c158b5b10be2
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:0e35a8d2cc3a06a39dc2f79a9f3bf0a3f46ec95c072ea6f4ac19f564c8c3a872
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:007fb9468ac3b92126ca7ed1fb7291edba50b00740e41db850e10f6d485941bd
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:8200b0c7a2ae370d51f02c0fd83c03e5e028ff0629d1230b4bfa4d5bf7982a13
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:817f23a86900acb958fbc917019cfb65938913a2460ed288749184b4984a9bda
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:5b8f94d25bc7fb5e2d4a583e244a0e1d6b2fd3af2c557b9b1c73ca7a8fac5cc9
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:e2dc679aabcf18f52ac16fb2652c6db6165b0a02178664cf87960d6155b198a4
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:4418a377da00f9aa3b83211d7e275ecfaf1e530ed1ca6b8875ea5e9425dcd583
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:b5daefe15592b51ffde9874727b4e4d8507ba3243bb61659957d1b05562d0bff
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:801b1bf3a5b3ffedf117442c42d9267dae7735ac300414e16fc704b3fdaad967