Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

1.30-debian-fips-dev, 1.30-debian13-fips-dev, 1.30-fips-dev, 1.30.5-debian-fips-dev, 1.30.5-debian13-fips-dev, 1.30.5-fips-dev

Index digest:

sha256:cfc64be5fef02facf678a3f12fc84758e3a9213cbd0150651ab45a14b7d88416

Manifest digest:

sha256:56e3913277a957863b8f92ee68719b3d430847df218ad31fe28c779d58e9645e

Size

25.65 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:02981f41a5db113bb2a58a48bf2fdf328bbc2415051035c695c0a1250d84c882
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:9fed7f68f150527b85a9fd94bbdaeb560382d391d0e5924af897250718786f35
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:5145ecda4de27ceadd1aaa0fa1f9e900c763d1ffc1904aaca036640e1fe8697f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:94835896fe1c84b4faa52f4024d0483fa07e6ad6b13a6410c3df15e8d1c1a65f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:644d97ece8f5bcbf8af753f2927d78240879ad321df455bb3ea7d2d6b3bb2b39
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:4af3a001c89367eeff8cf8779c169a019b41df090ffc52400fb2b417ac1a0c0b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:0e82355a6db892f0874d447e515423cf6993510145de749f33f7e6194ceebfcb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:0f626a327de02204e12d483614ea9f04a990c8081476f83b7a598727dbc2e19d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:7c588f89b5ffd9744fc8a03719bad897d3587e473c42d803320285cd51caee71
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:e83756486eaa1adcc1b0074b13a77bbd4a598fa09553ba817e787cb9cb09e6af
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:bcf1080cbd00f5ba36645aa0660bede1c54bb5d0dadf20375c3c3721b9b3820f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:5f5dfe9856e6d263f199e557a34d363293407218910ac926ee6a94c44c7dbd6c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:68b9e976bd6ca4475824613bc8951d4a15973e9c15e8e59dcd60c2431c575417
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:424ac393a3eb7935ad8c392be54ce0291c0ce379c4da5c6c7fdbc59d64bfef00
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:5454a2b00fcc3182b81026ccea599b639d88ead6783a7666730dc6f2fb16065d
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:e710c1993acb211f0b7b66627ca7a561465d1bc75278248138d18d7f63fdff52
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:0db751c25780c611bf088d0d63d3de7da030c37e297f7b4be1a62a1757cd2e9f