Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine-dev, 0-alpine3.24-dev, 0.9-alpine-dev, 0.9-alpine3.24-dev, 0.9.0-alpine-dev, 0.9.0-alpine3.24-dev

Index digest:

sha256:a94f65b06d236edd1f7856061f6744b02805afb4757cfa809c6b8d9d25ededee

Manifest digest:

sha256:1e6a305edf7e5d0faf1361c9581c4c0a88a06d6b93d3349e4685fd99be948a95

Size

40.59 MB

Last pushed

3 days ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:f5fbb071dbeb506c3dd634fa5108a7cb368d86c7721253bf3cdda3a5c04bcb2a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:acd0dbc67346515f1827d981b4f78c924159c7714b8167ae8d93ff4ff0d91c66
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:8c4c7a5231ce6601d69bbea61750fafa6c5517b4f9fb84614b029760afe58f59
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:97bb8d389fcffff0e87d2f1d2c4b7e1350e0091077d6693de832bd3ce96bf1cd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:d4f1e93bc8c643af3e6992c7cecf841d7e277047bcfac3b3093003534f73ba2f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:25748fd867dafaad03e0eaa419be0a755baa2c39f0abc845fb3b5528cf6588bc
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:5b1452992d207004a97e2b4d6c1481697e84b80320054be456262883f1673570
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:cf9910258a2a90159c77139e6c4bfd842b5516f788da24151a378f782f6a193c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:db061efa41c2e6424eaf605a0588cc11ae5354046699b8f48a14d459c7c42016
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:32a79606fcb66698418e36bb7b955debe8955ce48b9757269caf832c37ff3d1e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:08bc45e0681f7cb275494323e37a307b7456dc7cdbfa1dd2ec2f88f0e1b3dcee
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:03c36a67145a3038bb6a02a3f2b6fa6688bc19cfe9bf83ba88effefe5c53de79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:7dcdc279c1240fcaec8df49557e6007b739c6c9284ad9109e3470310fd41430e
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:fb607688678f2f8b557fde5614761fab81e6848045156f4a2a51594e84eaae2b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:0558b7c8d06319386b2d98c393f1c7706b0dfc3ccd0c6a3b36f4db0676db93d4