Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.11-alpine-fips, 1.11-alpine3.24-fips, 1.11.4-alpine-fips, 1.11.4-alpine3.24-fips

Index digest:

sha256:a12b6879829ce875ccde23f18a6403e7fc63cc81d1cd973e7faa1367780766dc

Manifest digest:

sha256:54dc1a64d26e0a10d3dde9304ac827659af65c4586931bf9f1a0e44f6e57845b

Size

10.04 MB

Last pushed

4 hours ago

Vulnerabilities

1
3
0
0
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:18a1003bb264f95fdbc484c8f3762a0ed9b12945f2934dc880586ae3aa629666
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:836b4df4e89dcae3a9941336c608cbd9654a305de41b9854762f802a7f60cf95
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pushgateway@sha256:1faf03010e6ca7cff279c9dcf9b5ed3a17a56e3b21cfa9a501a7efaf400ad9e8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:37bd1f635c115fc685021ca7d8935730411e884ba17a454bb623a853bcedc0a9
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pushgateway@sha256:ee5484f96a29f7ee794211168e35a5f1b50de8e8e4a22ea61236b5aa98b40414
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:9f12db41b8a6c77e2ef7f941d72e6ea0f3c5375b427ad292d7ae7e2a4a9c7d8e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:ad9bdf326e06b44c11508b1081ec9e1bc39c9937f7878a484630daeda0b9ce24
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:8ee0bef42e98814c99c0e3c17ed8d75a82f25e62b82cd7499334d1e4f08464fe
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:da33c902d3f52d079d5fcba866188f03ae17c6210424ca64cdeedb3626a045bb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:c3607c0e57119bfdd120c6c6551905efbf929e4958b8177f1b456adde786eea5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:6070b1de8f9af2b1d6eb0974a8f429ea870a44e0b1ff06e6ad301a95d30c5d02
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:c669aaf92414dd91702897e829374456f2c039a0bff1b20c950654739ab73ba2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:e5f71aa2f7e8faf194ee8e8248fe116fb2de5e1c99ea8a5fad16e0f2d8fa8e90
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:364337010ece2174c7e293face4662c0476eba57ee11d3a90d4c4074f0df374b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:b60f09bef81b6826491bb52f1f14eb2d38e5eeaa9127bccd34ff4640cdbb868e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:2157ec282c4f789f6f9478c3e22127e0b999ab6963ecae554d95b4e885f94af0
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:5be64e91e6fc6ecd3c4379d224af565117100031b0b22ed74d640f3fb7c6f55e