Sign inSign up
Prometheus

dhi.io/prometheus

Prometheus 3.5.x LTS (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3-debian-fips, 3-debian13-fips, 3-fips, 3.5-debian-fips, 3.5-debian13-fips, 3.5-fips, 3.5.5-debian-fips, 3.5.5-debian13-fips, 3.5.5-fips

Index digest:

sha256:6b4d373e2304d5f6cba6b6c4ce37ca4cac935bb51f4c3ded990812d39999a40c

Manifest digest:

sha256:8cc6ca3b9ce25d837c963219eea0d1096d5c36a3764292b552795a7074c82455

Size

63.82 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
2
1
0

Support

Ends Jul 2026

Request ELS

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/prometheus:3-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/prometheus:3-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/prometheus@sha256:c8e6713187b31c7d190d3367767ec61340287f6097e91410fc0908354806b09a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/prometheus@sha256:8d5f20712c198f9e53bda30f12600ee112e317d1e16397cb26257ada68f70b1f
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/prometheus@sha256:30103d7d60dcd809e873a20180242b36600f4233698de43fa8c35fd13ee1b99b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/prometheus@sha256:14dfa0142b899edd36bad2af44d5895943ad161bc95835e40dd45f5eb452106d
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/prometheus@sha256:ea4ff776b3794b2d84cdbb52855cf18cca021149e604de38530f9f98a8349b84
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/prometheus@sha256:63adaf5ae707f57e5d6dc5b7b99ad18ddfa78b7bfeaeea45a894e18c024d8270
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/prometheus@sha256:ecc6ee5082dc4650b39fcbf805edccdec54f4f486b95d8a2f34e0d3118024abc
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/prometheus@sha256:f3e3554e7ad2d13225ce15c628120c98a6dccdc3a61b069edc9cd012d2529ca0
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/prometheus@sha256:6ae72751c94e08f4e8c64ec353132d9bfd5528983105a0bbb721514396990ed7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/prometheus@sha256:20971c142f20424245d93bca10527e8c3029c72e5ded6e793e353884d6a00e06
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/prometheus@sha256:41c497a85fb68ec27710e937a7f7a90a341ecf33738ba673674a847a592417c1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/prometheus@sha256:214f3e97ac03477bbba582c7446e34ac1178a2506e0b231dc4a76f46ae68e75c
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/prometheus@sha256:79dd3e6c65ee813fb66d537c3574115595e763e61dfae998add6f372af75084a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/prometheus@sha256:5f5883e3134fe10e11441c6a3e659e3584e43025870728fee7025cbd14ae1d83
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/prometheus@sha256:8dd05822cb8ddeb1d1ee22d986a14d68ffbf693853136e122eb8f19799195af4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/prometheus@sha256:4b32400de8f8267724c5e7c2d285792b14b3bb98c6ae75af1d017a74b7d274b9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/prometheus@sha256:06f46b7e488147bf89b54aa17ed6fd59358000397b0d62c60c7285801d0b656b