Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.31-alpine-fips-dev, 1.31-alpine3.24-fips-dev, 1.31.6-alpine-fips-dev, 1.31.6-alpine3.24-fips-dev

Index digest:

sha256:d3523f229c628a921ddfebb85b641e5f34e2087da547c07074f1392f535f3b6c

Manifest digest:

sha256:66ef176ac9fe342b327668f6637480ea4470bd678b8ee7013d68f555752dedba

Size

5.15 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:e49fe7f980874673982cb59988918cf95ceb2015397be4db89b54d920107db10
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:54f519b808b2c3936563e9223400139de9082ffb1d39e239e5b1aa4f07d8d34a
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:7f3335e398b35f615d889e47121f8e6c8877d96d18da20cc140afa1cf94d3c1f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:c6a180df99445624d8f3c4fbc5193afa5bc5dd9f67b862504f4666691013c31c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:12e5d0813c8607d198e0ed1a421da399d6e937754aeb83476a395d5105ab133c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:b087f96a84a7da509eeb9e597253a4703ed5e3fe065b8752d16c0ff0a8e5b318
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:5b7b654a7b6dc347969c41e1b8fe400c6dfbaa499700fb91adb9be3af06a3ede
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:9eaddac033b35d5591f74a3c4eaf2be28da6140f3649ab6a86097aba6beaccdd
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:37de04d71c8becbd4600b619ee8d87ce5a8e6234dd991afef2d682f720036245
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:819fa0bc508e69e9095367c48f9fc0d38ec1c6c47045aa2dfeda9d906fd9b1f8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:cea4a94f56557141349654613c390697ebb29fc4e2af9b1e6cbe696266f95194
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:91e11d299dd270aef70004d61bc3c03343832e969496b6b20790d2875c2c527d
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:986d9de626f21229e16d23edad32b64d0ddecbe256df5097ce0b920387dc8a33
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:ba83ac98c6159e55d0f3a8d085c94ce4713cada6962984eefb5876ecaf5fa0b7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:81812558ac63828f24cfcca3aafe5ba53eaaafe25a2965ba98d7b99d755f0e00
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:82838df308dbf164c1e0abf67cabacfebca2497682187371ec83a4ba61907ea8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:70475ecb3ba6d956512561fb9cb5c7b58ec6eb719222ebd5bd5bcb0dd91c237f