Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 2.3.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips-dev, 2-debian13-fips-dev, 2-fips-dev, 2.3-debian-fips-dev, 2.3-debian13-fips-dev, 2.3-fips-dev, 2.3.1-debian-fips-dev, 2.3.1-debian13-fips-dev, 2.3.1-fips-dev

Index digest:

sha256:535d68ed46e890343b43fe31d1466806134456ea79fdc20c8bf7d29dc616de08

Manifest digest:

sha256:77c4d2d90fe9c50148be4cce2d75f0d4dbbd2549e3050407f8a5861de2973ccd

Size

121.47 MB

Last pushed

3 hours ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:2-debian-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:2-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:f30e74dcc20f3424ed486897a34dbf5f2b1dfbc1b6880c2bbab5edd565635029
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:de8afb7ee154e6c4cb537b74581b3603fad91800ae1b765dd27317d0d2832cf6
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:7d2cbf32702b1d84b90e05152516fad7840535e4969372a4b5418209e7611883
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:fb7a696eb1dea8f9be7fd029043caa3f809371fa093e1d4625be4b98f9d934fe
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:695818f56ca8ea43e459846edbbd4ae192bbad3de59905de7ca6de9c66111382
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:56dddf6e4719ad387272e7fd2328788c0e550ce587e885cb18144f9c1e9aaebf
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:6ade8d9e5a27733fb29b9b7749c6063a43876f5726080cf32b1f0e3bf1ec6d74
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:d7d96348541d47dc0db762741beb7bd77183f33b73b1171bdb743b01642a422f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:2ea9dc84a299faaf43501714f66b47e7efe0b1fd7cbf61a757f0789d7f7cb5e8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:3ca2c0a0879423e406279bb97b5c8dc0751bb01f1b2752b18294093d6000ebdc
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:cd969a61ef6959ec375b084d4aa8afb79429935fe4717b5977ba91f0eeff0e37
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:5fee1362b70b3ca228817126b906bc4f51054f2c6cf2fef5b35e440f9e606997
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:06acbc37f8aed1c63fa1b6d9a05add77ca6ca158d5ecf01b66dd4764ae5e6006
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:90f420572f7cfadbefccce75aca6ec08a1259b233ac3d59db2dcd5ad7475000e
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:b8e2226f71d918314072cc0e4db08a10bf290c91240e94ee9f45ba6ff1504ae4
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:922ecefd3f970de02a9da78baf7a617afec5340313b555f7c3c7d1de62ffb0b3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:5f524cedcca4c58dc65fbc89d5132ee36903bab55a5f1ad3553fc24b2b1a58a4