Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (dev)

CIS
linux/amd64
debian 13
Tags:

1-debian-dev, 1-debian13-dev, 1-dev, 1.31-debian-dev, 1.31-debian13-dev, 1.31-dev, 1.31.6-debian-dev, 1.31.6-debian13-dev, 1.31.6-dev

Index digest:

sha256:8c5722fed4a1c4847035fb6f13ab866e53cbb43bd31d12ceff98ef92f3c2189c

Manifest digest:

sha256:8c242dee50a461812d8812e65f7b490c067da96059d81e5f9573c50af7d8a3d2

Size

24.91 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:e55494028b435cc613f31cdc870aa460a00d5c14dfe0cf63ed505cc55a1d9f64
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:661cedc531e057377246403e741debfd01ce10d7d7a42aad821a3bd728166162
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:84eb14f80d79d9e92bd68a12bcf3e4ee4f383ff576469a0b81ee78ab4da772d4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:1ddab02bec4ba02e5aae3f0bf14a64f91b7b94dd9e492d0628bcea3632738175
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/nginx@sha256:6b2c9402190223d657bfcea663dc1c838d4fe111d9c518b5da48ba129ee87817
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:50eab28dd9b3ab99a0564579f368ae632702d4c5d28e99c03473efe0f675304e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:5b6310ee367ac6dacd73e708fae0225f1212e55c39d313a8ca3fb1514fa040c7
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:774f87322901183d216945bc1b055085a120a1f62db06656ba434dd4ed2cdced
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:eccded758d0223394ec16431d7d22e388cbce441243e8c02967fbbae452a8f7a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:e48ce9f5523d04e8f473bb5e94e4519b738d04d9f0a0b75efaf09453f6c4fead
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:3e99ee23c0be64f4da253e1dc85ae19c01ebb3cc2767f7665ed977c05bad404d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:b31fa24259892512af9a1c3dfcd389df64cdcfcac848ad293b928857640eae8a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:0da0656ceb84e623996fec4b979c1a6b447751a9b7ab37dc831f6bc3218350b9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:897971a7523b9d1a8ed72d2a16906587db57cb5e0946398f796bbc791b307748
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:5a87f3741a692ca2171a45d581fbec4120d1b1bed5929668d04041301f5ef20c