dhi.io/pyroscope
2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.3-debian-fips-dev, 2.3-debian13-fips-dev, 2.3-fips-dev, 2.3.1-debian-fips-dev, 2.3.1-debian13-fips-dev, 2.3.1-fips-dev
sha256:535d68ed46e890343b43fe31d1466806134456ea79fdc20c8bf7d29dc616de08
Manifest digest:sha256:77c4d2d90fe9c50148be4cce2d75f0d4dbbd2549e3050407f8a5861de2973ccd
Size
121.47 MB
Last pushed
3 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pyroscope:2-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pyroscope:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pyroscope@sha256:f30e74dcc20f3424ed486897a34dbf5f2b1dfbc1b6880c2bbab5edd565635029 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pyroscope@sha256:de8afb7ee154e6c4cb537b74581b3603fad91800ae1b765dd27317d0d2832cf6 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pyroscope@sha256:7d2cbf32702b1d84b90e05152516fad7840535e4969372a4b5418209e7611883 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pyroscope@sha256:fb7a696eb1dea8f9be7fd029043caa3f809371fa093e1d4625be4b98f9d934fe |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pyroscope@sha256:695818f56ca8ea43e459846edbbd4ae192bbad3de59905de7ca6de9c66111382 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pyroscope@sha256:56dddf6e4719ad387272e7fd2328788c0e550ce587e885cb18144f9c1e9aaebf |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pyroscope@sha256:6ade8d9e5a27733fb29b9b7749c6063a43876f5726080cf32b1f0e3bf1ec6d74 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pyroscope@sha256:d7d96348541d47dc0db762741beb7bd77183f33b73b1171bdb743b01642a422f |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pyroscope@sha256:2ea9dc84a299faaf43501714f66b47e7efe0b1fd7cbf61a757f0789d7f7cb5e8 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pyroscope@sha256:3ca2c0a0879423e406279bb97b5c8dc0751bb01f1b2752b18294093d6000ebdc |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pyroscope@sha256:cd969a61ef6959ec375b084d4aa8afb79429935fe4717b5977ba91f0eeff0e37 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pyroscope@sha256:5fee1362b70b3ca228817126b906bc4f51054f2c6cf2fef5b35e440f9e606997 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pyroscope@sha256:06acbc37f8aed1c63fa1b6d9a05add77ca6ca158d5ecf01b66dd4764ae5e6006 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pyroscope@sha256:90f420572f7cfadbefccce75aca6ec08a1259b233ac3d59db2dcd5ad7475000e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pyroscope@sha256:b8e2226f71d918314072cc0e4db08a10bf290c91240e94ee9f45ba6ff1504ae4 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pyroscope@sha256:922ecefd3f970de02a9da78baf7a617afec5340313b555f7c3c7d1de62ffb0b3 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pyroscope@sha256:5f524cedcca4c58dc65fbc89d5132ee36903bab55a5f1ad3553fc24b2b1a58a4 |