Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.11-alpine3.23-dev, 1.11.3-alpine3.23-dev

Index digest:

sha256:46c5b5ba9dce9a23a45f20594012a34e4d0f853c94bd1ec0275eb50cf261f78b

Manifest digest:

sha256:2902c53b291101e82c8098a626337b4c55a7c57eda306770b7b34cc19bea47be

Size

14.42 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:7adc13126cef3bbc155d8e7d822cdfd254d531f73be3433f13144612d6d6b1fe
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:269da0d6aaa03d97d60d05b0bcf84f6074d6f85f7857e5152a949752f643fbad
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:bfc592edc2d75ae86318c7d80eef2d3ec95967574755682bb5f6508037eb8dc2
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:1de07e232402475cf9a4f59bfd66f7e8a9cdd293a1cfd406918bd4d3a4d86d80
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:cf2a2182cb6452b627a08dd3c6f327b4a4d220011ed966ad08459535768a5a78
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:d5bafdbd410ff25e7772df324b9a1889eb9b6fa945cfbc0e0d503fabce193a14
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:d54d8d0ae55e283eb2bf42ded50e01c6ac09ed8f1e637dca6f3a26e7710b3b12
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:59695d46909b117584fea30f98bfd2acf86188c583497f5d37a4458d0d641a40
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:68049a4b270ca2d0380dc0ca2149b2b56ddf258933d837f58503547696466c6e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:e12604161d1588f02917a0f05b94d82a31d59af688a8c70cda3d1578257f74c1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:821df5a89760cba550b45b1d453cc5dcd3a6fa5fcf45f0480cde35d55ab0604b
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:73ba961f761a8de080095290fbf505c5fa51a086929d4835a592d20f518a084f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:4182d32f254bd85ad142ba9359da3940eec1bb5242866460b9231bbad8b134b7
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:492da8da06303b71621fe83ed86ddba31649b5a99ff5c56ab05f0014b57be82b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:663fa3ec7d922762a0ee8ad1619f672b466deb26dddf75c2a3ef869988dacd0e