Sign inSign up
Uptime Kuma

dhi.io/uptime-kuma

Uptime Kuma 1.x (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.23-debian-dev, 1.23-debian13-dev, 1.23-dev, 1.23.17-debian-dev, 1.23.17-debian13-dev, 1.23.17-dev

Index digest:

sha256:03da91ba0f89f9347ccfae385106f0ad508db1810e15236c4881ca17002544d2

Manifest digest:

sha256:cd74931ab38083226f6425756f9d356de51e1a14c8d20fc9fd3701b014fb0507

Size

84.23 MB

Last pushed

16 hours ago

Vulnerabilities

0
2
4
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/uptime-kuma:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/uptime-kuma:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/uptime-kuma@sha256:21009831f8541ff742bf0ce6d15df78047295031e420a6012cc68e44109114e1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/uptime-kuma@sha256:ed76e621af71874c2c98c4273df304f8703d90703856465bc9372b0318b5e4ef
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/uptime-kuma@sha256:fffc5799e63afbbd9fd60bdbd4f8cec1a1e6843d4e61bf27c70001c0bd337fa4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/uptime-kuma@sha256:23654bb195559493ba25c6b0da616567e48985da990db6a352afd90383971fc4
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/uptime-kuma@sha256:3ff4d9eda705843105b9b04dde88b9d43abf58c59342323893f6b89d650390a2
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/uptime-kuma@sha256:204e0e7fc0b8a1aa5878c089ac72f0f62b2c2e247c63e3a2a218b6e5fb6f2885
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/uptime-kuma@sha256:a91f461a5162823a936557302159ded3226c76efeefb6af7bbf065d95540e77e
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/uptime-kuma@sha256:8d8158d218d25710aca5cc4c7122ff9ef493bb034a7ef9dc7b2b98e2fe9bf7de
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/uptime-kuma@sha256:43b36e3093e0cf093c97d2fe3f3016a4a5542c7bae3dfc7350f7b0a20ca90ed4
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/uptime-kuma@sha256:8bffe96950bab18831bd115008ab99928b5468dc9570a0aa8b17e9a4d8aa9bb2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/uptime-kuma@sha256:542578f40bd7bfedf58a67e0c48e85e654f86a93b19bac60e33c0a02067dd15c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/uptime-kuma@sha256:e967c1c3d6582e5a84f991bb729ee926cc79829ac9914de05bc2701644c1e422
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/uptime-kuma@sha256:73417044ff8dc7717fecf47dfddbb2f7b287f3b22535296099858f034ca9c4be
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/uptime-kuma@sha256:93bb15f3a4833ffea91e0ba4a6374186007dfd8e397a1f5fdfeea048210404c0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/uptime-kuma@sha256:7166c0e4474bfb147dadedaade933e39f51317c2bcc83f5266741559770270c6