dhi.io/pushgateway
1-alpine-fips, 1-alpine3.24-fips, 1.11-alpine-fips, 1.11-alpine3.24-fips, 1.11.4-alpine-fips, 1.11.4-alpine3.24-fips
sha256:a12b6879829ce875ccde23f18a6403e7fc63cc81d1cd973e7faa1367780766dc
Manifest digest:sha256:54dc1a64d26e0a10d3dde9304ac827659af65c4586931bf9f1a0e44f6e57845b
Size
10.04 MB
Last pushed
4 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-alpine-fips2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:18a1003bb264f95fdbc484c8f3762a0ed9b12945f2934dc880586ae3aa629666 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:836b4df4e89dcae3a9941336c608cbd9654a305de41b9854762f802a7f60cf95 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:1faf03010e6ca7cff279c9dcf9b5ed3a17a56e3b21cfa9a501a7efaf400ad9e8 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:37bd1f635c115fc685021ca7d8935730411e884ba17a454bb623a853bcedc0a9 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:ee5484f96a29f7ee794211168e35a5f1b50de8e8e4a22ea61236b5aa98b40414 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:9f12db41b8a6c77e2ef7f941d72e6ea0f3c5375b427ad292d7ae7e2a4a9c7d8e |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:ad9bdf326e06b44c11508b1081ec9e1bc39c9937f7878a484630daeda0b9ce24 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:8ee0bef42e98814c99c0e3c17ed8d75a82f25e62b82cd7499334d1e4f08464fe |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:da33c902d3f52d079d5fcba866188f03ae17c6210424ca64cdeedb3626a045bb |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:c3607c0e57119bfdd120c6c6551905efbf929e4958b8177f1b456adde786eea5 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:6070b1de8f9af2b1d6eb0974a8f429ea870a44e0b1ff06e6ad301a95d30c5d02 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:c669aaf92414dd91702897e829374456f2c039a0bff1b20c950654739ab73ba2 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:e5f71aa2f7e8faf194ee8e8248fe116fb2de5e1c99ea8a5fad16e0f2d8fa8e90 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:364337010ece2174c7e293face4662c0476eba57ee11d3a90d4c4074f0df374b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:b60f09bef81b6826491bb52f1f14eb2d38e5eeaa9127bccd34ff4640cdbb868e |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:2157ec282c4f789f6f9478c3e22127e0b999ab6963ecae554d95b4e885f94af0 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:5be64e91e6fc6ecd3c4379d224af565117100031b0b22ed74d640f3fb7c6f55e |