Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1-alpine-fips, 1-alpine3.24-fips, 1.31-alpine-fips, 1.31-alpine3.24-fips, 1.31.6-alpine-fips, 1.31.6-alpine3.24-fips

Index digest:

sha256:c14d52099a62f30bea9ef5368c1181d700035f142a4f971e06b2fb6e61082e29

Manifest digest:

sha256:74e051e77a141602e93b625ea38cdd8ccb7793361cfc5721c611f65556c9a54f

Size

4.92 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:adc647c7e1df0089920ae877130c200c11ef8bb383537c259b7d299564082c58
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:b640fb2cac59a4161d9acbb0b14c61be22fca6b7b08cb58e9a7e3f24b5157010
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:b868ed436236e68a8dfcaee2f3b85017f144940e5bd45b94636d95d6672108d8
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:185be5de8783e3af882d1d2b4685d88533b908fc67bac65d3d816b58c38076e8
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:eace913731af94f6f334aa148c7fd090d7562fd239ea471dd48dca10f75c91de
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:c58f6d3a3c118ac020d9a5c7c11353162110d370275e26d12e5069bcfd37a571
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:0e7e7f71b4b446d7932d207fcbba81cc974cebb5838830a5f0ad20a71431832c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:22f9686b7819e1ce26102f935c029dc66ad084f05aad29c2d6c63db2df137902
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:8ed212cb1ed153cec9a4a3802186689aac30207da20e4268c366d458bbb96dca
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:47fedc5c5b01dd2b49626fcb8e6120af420d9b1678b24a373f82dae2d61d42ff
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:da422751518406f434d6bedcab7cdb2f27f173c1c69e84e6063e92830dad43c2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:84a3419994233c94fa3f861ec475f3f27736cbfb765491e90a7b83a52480775c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:b50a8a771fba9530b2fa25279303b1903fe54da5e02302cad253228e9110077f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:3d1405fc4fe94fd3444d505dd8ad4ca612fbc64c42747240b1c2948f05e2d2f3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:0203a2bc8166132349425e27bf8bc0e9c379226ab53cc7780eb1b2f71de4bf0b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:cd8f962e1db71cdbb3625cf775a593c052ba817ae20452816217fa4bf1aebe8b