Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 2.3.x (dev)

CIS
linux/amd64
debian 13
Tags:

2-debian-dev, 2-debian13-dev, 2-dev, 2.3-debian-dev, 2.3-debian13-dev, 2.3-dev, 2.3.1-debian-dev, 2.3.1-debian13-dev, 2.3.1-dev

Index digest:

sha256:a9027cc2e6b48eac9eb16622835e4dc254b589de8fa5dac32d87320216e10715

Manifest digest:

sha256:c522f094111c139d4fb437ace1da6fdd83f3a01d56b4f35228174ffcc8b44256

Size

120.74 MB

Last pushed

2 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:2-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:2-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:c712586544c041c1779457b76935276737ee15563f202c68c65af351bcd45630
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:d08e9822c8d5ca92b9676258c274e04e2ea35a457556981b6da88c25af0788e4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:30a04906b6e425bfd73d37cd4654a6fcfbec6a96cd6588fc529e18fe78bf5031
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:b4f02a65cd72a921331591518b7f761bceb3a5a95f1020bc3581e213cc059f3e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:d798eff63003c20c43b06ac9ece6c98e7c4ce20b5e08a339b9fbc7bd7cf84181
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:e1bc5592836a1530e0842bad0fbc6cff2c07a70a448b0340351020ef8c2a6129
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:3b2120617e4863ac9a037477f93241b0dfda0da681ee68ceb8f4c34dafe716f7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:448eb517c54051584ba063610329659ad1a7489da9baadfacb1bd23f913bc5b8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:3f6a629157c17260b94cd57e07458982ff61d98e31cee9ea4470465ba7165207
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:6d0c10963dee80893c1cc19f7ec7c2f3014e3cc247e860e009ab331691898185
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:157f7d63fb5e3b55fa66b3f84df1c5777f5211ab5aa01c31a9f2417008904595
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:caf84a07fbf0be4a37adac77af43dec3a29937cad1dce1524fc953ba44adc121
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:3f8a71f87a8f65778bb816df870ddcd9d0f46a44c527fb249d66946044704022
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:69869724a9f20c604e68c84243fd37e9b62dfaf62cab47c725e757ab63f3d0de
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:c67c0677d093540fe3e2cfddb4e317e7c56a12687496b439be670b204cea2733