Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.9-alpine-dev, 0.9-alpine3.24-dev, 0.9.0-alpine-dev, 0.9.0-alpine3.24-dev

Index digest:

sha256:e4be020a2385dac721a1a3cac290940394fe20d181e92d33b21b1b7d6bfca74e

Manifest digest:

sha256:72829ded7b0ac7cd629da1ab06bb313592973762cfa6d5111a49e60c5086874a

Size

40.22 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:430f1a09d906869a74e38d26bf5015b0ae7424a32212cee719103f75902c1c7a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:7f917ca0f0689a968d7007ac7a40b72c3cb923caa7baebc7fd932d0fc5fb881d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:a753907d73516f859a2db83a2933f057b522201d0bab0fe1903955c2ad3c92b7
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:8a710d78259a66cafb083307aa571c530d30bed9095f9aaf6e47d40a135c6005
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:01dac0447ebe44ea287d989a7be441180c79aa90293d52775a257c8d3f6ec6c4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:0c3455fed7478ed5909aa901048bf87ea5a5d025cde3a097b9cb145e7d158173
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:28a8a0533fcb765ba0d6994bdb19a177fdcb92c12d1378e7ca6871ba11d4dba6
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:d5858a5f5cb65ed22c40a317b4f4639649243388dba3cc43fdeb3c47b6ef4b9e
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:bf944aa5f3ec07d03ab8cd078fba80fe8ed90ca0b8da96957dc6a3f9e4f42192
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:4c3812f7b3bd4b4964e7df08dfcf3c2d8aa6a67d930c0cb6242a8f6c45220c32
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:7146b7c6904942176bc4bfd06cfcb371b94bb94a36025d093ab94c6119c254b1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:4dc633ed0f2d63d3198b24852e09c1ba6fad564d589bff0b9e3b06ae773daed5
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:aa6b2e09a8fc1a8bad2dffd1570e0bc086b5829fdadab5b6a66de692e1e37add
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:a5b5bd211aa70c5997bcecc9035dd8859890ce59c2f16ed64c0f2405564041da
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:8c8a9db81e25d15b96ef0b249e65f7855e14286a8b7f479c30006f644f29b27d