dhi.io/pushgateway
1-debian-fips, 1-debian13-fips, 1-fips, 1.11-debian-fips, 1.11-debian13-fips, 1.11-fips, 1.11.3-debian-fips, 1.11.3-debian13-fips, 1.11.3-fips
sha256:f8afde9e29881a527c88d443fa0918d99d70dbc2e4b532394bab61e82cb16326
Manifest digest:sha256:fee2518efbd1538a6a9c0d807783c79264810f4aba52acaf65c74d77e6b93986
Size
15.11 MB
Last pushed
2 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-debian-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:d6fba4103bbc938e5d723c80644e6496c20e310a4c3316616695b1b75a0b6c12 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:d3e76ee71a89b744e9b6407189b74419ef6a502f68f6c620bd6ce14319f64eab |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:27da8c22924e5d9316e761ed112c9a855ec7d84aafa2f3fbc806886a9ca12ab0 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:75ce55403abd34bee6a742fdbc732022933b3132897fd5ef8134c8375fe358fd |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:39f7f1070b87129fb47b06263bf95bf8e599cf530e443926e9a9a36a2718c7a2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:6e5cb03c3ba72925bca66669d95314632ead588efb276f008df341939d7d2878 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:9d040a6592465076f9b90a88ed6da4779a8fd7996520e3688f8a1f774bfdae49 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:71ea73da8de7c0e2d3bf0fc9fb954aa0d1e4019cdd1db6264fe30528e03400a3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:44b038e9c33c3c3c814fe9a38566b3bd01588f8f33d869f3b09584d357edfcfa |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:2ca9d7847b434d052a722b35101f6fd01443e883b9e2a11cf31a276a6172a1a5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:76511bbaebcbf7768360531830981f470ab8078cbf5d4cc56b8cebe7640fb7a2 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:042204cc8b4f5aba9df38352ee77ec964d48fcbd6de692e361672b05a04281a3 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:08aba071789740a678db1040ffd543015fc3e42e3916f4b4ac38df068c909107 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:ad90b2586f062eecbc67f7f28ec72c77b9305c2d11aba4d53f8fb082c6790bc4 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:e82b56e654f874911c46802a77c0f790a7628f2a36415e9debe876321d8a8af3 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:39373ee374afcb028dfce400284c43eb20b5bcda7aa0422d552c7e8e511304e1 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:25523579cb3f02e6c23d43fa4685efcda5681dc3339a8ec03e67e4ce87eb42c1 |