Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.9-alpine, 0.9-alpine3.24, 0.9.0-alpine, 0.9.0-alpine3.24

Index digest:

sha256:2213442d8add2c9ed7603761706297a724b6f47aef8c72828d13dc6786550178

Manifest digest:

sha256:9f16f1463658270e15c9ffb83855a004c6517765b4003545a77e827d25b5a0d6

Size

18.30 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:942ab3075cc7b6eecac45704b14e78e6101ee412a6ab6fb0e156157cc15f33d9
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:da0b225a7f5972086905d47d624a8f612b081b491eed32bfed39bd43fcd498c5
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:9a031a0f9f0ae5c8dc387070cafe48a7862c945271c2dc241fd979c233f027c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:978c72d86190694014643328c2e520e36061c971482ead9afa9a45174e1e2504
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:ad03724d54829e8d070f7fcc5ea8209ec259b51bfec3886f1f50b48282a61190
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:e2ccbade28641d9eab3e58e5fa5ff741ca046a83427c462da31d182a5a03f79c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:52ba85515f2e46a431e04580d5c2f1161c7373892ef0e305cdf479639736add7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:e50b05cf072dde0524dd46ac38d07883f2b3a84fc4a1850b15311e9e530d1999
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:c2ddf251005d6ffdf3e1c3204b79c47ecccf86b72c212b1d459c911e126b6cbd
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:98bbcb24b95535ead70b92234af1c42a58af0579f7a9c9d137172948a9aa51e1
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:3fac29442673ab6f9762487eb076695c3602197406cce95e99e7d339e74584fe
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:0d057d5951ea878c3d100b0cda8e57ddba91d34b408cb4d64d70ef0c75284908
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:311d33b90449dc5748bd741b7461645c14d5944a8f59382e1347c41f91bf74ae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:6030cd3b02216af84a1670ab77e94e42dec581dcb2eb50094440f4dd4ebda756
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:0f0a75ef2f7a26ac1b17c546a5042db80cc1807a72f389a644b104f49eaa3ec7