Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.31-alpine-fips-dev, 1.31-alpine3.24-fips-dev, 1.31.6-alpine-fips-dev, 1.31.6-alpine3.24-fips-dev

Index digest:

sha256:e599d25f74921e367d48d96e2a8b552c4cf4d5cef2c46b5180b4f9950f6c7e88

Manifest digest:

sha256:e825e41301b66264b3fe70d97f4d74cd8c84cd222ee0cbc39f9ef5866732e1da

Size

5.15 MB

Last pushed

19 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:9001059b4b6b0903cd376c8e50b0e1894e60dd8d82ff5edea74b3866d5b484b7
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:f1e8cddf0d05621e5d781d2cf879108b24467f5c51df48efcca5005331b528b4
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:09668a1fb7d2381bb34a76ef4bdaa994382b36d3310d0ae8687e27450aff2f39
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:e311571be6df328afb79d7350a12eaa472e0c1376e09f9c03c8fd9abbf5d4757
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:57badbbd08a2644598da2a6994ba2f4f89486a25b5b851d691ac9287e1cde50e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:64c279c220ed869db0080a4133c58a409c2c7f8f6af68d1125210f38d6d39587
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:69da8dea4fd12ab33fbe7e21b03fa07f62e803427f564693bf292634c978cb83
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:17783b174b97b115fe89e189ca81e41b087ba7e8edf8d2eee90b2d13d14d6729
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:dd8599459c58791ce7959d6f02289fa4430e7fbea9a1ba59608ed16c022d929f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:9637fed0212d2cd75bf2437aa48956def7bd2a76eb9fa208590e8267a02d44af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:bafe1b8a2773082398efc3bd4d93a5ced5b02060387d26f0d4d20641f7f9a543
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:2a8757a80e052311a84d91d3b33e1b69c525373720acb2fd84fcf6a2e1041e56
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:0c2718ecd5e1c456fff1a5910018b016816706a5312ed2acac5ec87fead9a2f1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:9fe00e0b6ada01d5b0f190e8d6fa3239531c343a9cc8b2c3772e21fc242b6a5b
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:32d149eba6577978130d1a0a242dd97bbaff3464e33702c5dc957cb11e3ad16c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:df8878c0177ebdf0f1368caa9db44e629d7c6c69715625d9749421aa76ed3a3c