Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

1.30-alpine-fips-dev, 1.30-alpine3.24-fips-dev, 1.30.5-alpine-fips-dev, 1.30.5-alpine3.24-fips-dev

Index digest:

sha256:c6c6110998a63fa703fe497fd133e031790b9bd47f842fd5dbb2a7c4349c574f

Manifest digest:

sha256:ba03d7777950aeae48539b205dc10d2e1a517d2e8d8d1713cae23f7dbb9e2e14

Size

5.14 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-alpine-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:7f756f4343e691dae0c126b2cb7af1024ccee42c57a4771fb3a26f1c3d2992c1
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:5fba436b991affcefe7fc7363f659881a6815c3e0f34818c03639816614145bc
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:e92287de5657a720c68ffd66be12c5d5e4c3f479a70b4611507e4d164d9ac1a1
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:f9f8d00b8410130deca7dca05c18edf24b43b8f5a4466e1d871a59999ed2fb00
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:63836c204422ecaae8bee6a04e89e13c6c43ec975dcebfe83b0bbc086f3d719a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:09fef6a95406db994c5a5f48efcf8053abcbecc428c051b5fcebaf621db89851
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:8e03329c7c3f06c09c8493ffcb340c90c0f1c8fea088d086210ad418648c737b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:120082d11dfe82e2d16b81e57e8ea9628663024ba7a215501021aef31ea5826a
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:a59b9ce3e546152dc02b5e9dd36a93c196b6e5d3050b47b37500a70e1f36e1b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:2c7a6abf54761a6cd0a0f2a99179dd6ad021b7ed2691d320a052b7fa2b13fefc
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:36dfc25e23e277fff884c2ff5307c3884cdee99c9cc6417c64b3515cae5b24ea
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:f66c5469c553cde4685cf77d15123c7058ce9811e2d099206ce145c9c3c315a2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:e73a2da9548dcefee6cabd214ebbe3444929fb2b472393e9e1dff194ea5338db
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:01885ebc0e7bd260ad8573e05b6589eef67bc623388350fcadc4e105ce14eaea
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:ce7cb95239b3719e3db1aa183351cb4f0679406dd164c017c540b364e1728b0d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:ff1be3118f1018bfbfefc2ccd3d58cb5e0d9f91eec834952e39ce34e56da95c5