Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (dev)

CIS
linux/amd64
debian 13
Tags:

1.30-debian-dev, 1.30-debian13-dev, 1.30-dev, 1.30.5-debian-dev, 1.30.5-debian13-dev, 1.30.5-dev

Index digest:

sha256:5c354fbbb97fef33238064d2ed1a6f50a0ce51e28e65c3908390781bb2e2b0be

Manifest digest:

sha256:3698ed538e71233ef5f474b5de8718d33515ebcb7bbf5412d38e06876f8a5b97

Size

24.89 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:8ce39ee9768b0982957df2062384c8e86396645f4d06f2f6c35b95dffc31f87b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:972462d474956cb2e8c74036c0e09927e32691428d8c809231d4db88f9bcab83
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:825e2d1ca15e5cc35120eba46267d16d1760f5d84f39df543a3225cf93465888
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:bdb2c580afefdd8bf73f46114d3a5196d954767daecd410b86f0f557e2bd634b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:df8781e5afeb088c42d73bed094356b74b9e74d88c4fbfaddddb38c57ea432d5
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:6a248d0a7ae658d2abf02687c65d98631210710dfe04552ca0c7d69421443973
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:b74316ce8a259f8ef9d57f2f77510ab76d78c0f08bbfabf93806cf3c26006b9e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:96f7bb657d5f29da34cd1ff49d9aa5c57a2ad446a46c49c5d00718b8397c3de8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:92f7f2ba07ba146cfb9d16181e45f6b6b0b82060ad23fddc95cab6cc8e01785d
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:b9aaebac9a7bce12f9d522717a616beb9d64f07c939fadc4acbcc7421c0e150f
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:9d2c5e46dd4cd4102b8893c5a3a686ced7d0eef01856151b9e9aeb9ca5086621
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:75289353c9dfac03fc914f78eb4e34861a35cb41ab15d355ef8991854658e85d
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:403693f9b52d37e870bab086718e5447f4d65dbc03c36ef05adb2703fe6958b2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:aea769a4b490e22fd884389b53535d2f7930a5ae79168cf51d695a226c5fdc21
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:d672903f30b3b0d4017f53219757b200fe4232b560f9e15afb4a4f5ed09a3a0c