Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.11-alpine3.23, 1.11.3-alpine3.23

Index digest:

sha256:4e09dce5b708d39453b8db02daad38624a323a4d8d4bb18c694677657f004919

Manifest digest:

sha256:3548d4ed2610e6f4f6a9b38bf2a64b25715835f21ac99c7fcb2aa1b2265dc004

Size

6.64 MB

Last pushed

16 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:da0525f7d15fd3bc851107cb2a7923a77273c3bea4199f50a10206496b5d2724
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:9b71f5a8126c686b6cd2ed224954ab84493f301b015913b19f91b61a281ee731
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:585540cd90df8c08ac030d9b6fea7ceb31059ab9884ad2f4f5e653079c13cb4c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:321b67c5425318715f38e01c5da6c49ee4f5d76ea8f5404ed09f3a98fd34c912
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:3add347f480c3fcfdd81e467d5332005efae689edf5c563e4b45bfd3dbde5378
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:513a91e24554cda267ec5544ebe84f033b51fc365f1096ec3979a4dcb2b47df8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:cc2c0cbf6b9db411c1732825c35973f1a06b3c8bec279b7b1b20426f13f0c228
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:a4b65bd9a6bafc36dff17b278694c84fb3cff3cb425d11ca13225bc10f8daf07
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:eb84292c4fff6bcc774d46038985086dd5cfec770aebf7ebd3f468348c0187c3
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:2b1feafba135ff6055826f7d9dc9c47cac5d6404f6ca84f285455ea550588ccd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:9ec0ba6a670e67da53fe4d0a0a7475212fcf74b584d2ef275b8a1e7df80e1627
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:61d0b3dcebe21794e58301f294bf024ff0f5fdfb166836a208d269d45bc8ea71
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:1ea5dee09478df2f42e1e6fe3ba4bea4c41c2a569e93068960bc90d702dbca9b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:14b9b9e2c1cf3b0593fdc5950abe5bc049749ab8c89c341224851a8f1fbd7b40
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:538c7dc83cf2e0ab5c67125ca9f75f88a831777efd2e38ceff61dd81ffc87ffe