Sign inSign up
Prometheus

dhi.io/prometheus

Prometheus 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.14-debian-fips, 3.14-debian13-fips, 3.14-fips, 3.14.0-debian-fips, 3.14.0-debian13-fips, 3.14.0-fips

Index digest:

sha256:25aabed947864c694f69ac41336875f9ce52909feed21a8d0554dee758caa7c1

Manifest digest:

sha256:b3f6266feeacb0bb533dfbf2cba4c1086af878c04b8bae2322dbb930d2c3a5bd

Size

57.90 MB

Last pushed

15 hours ago

Vulnerabilities

0
0
1
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/prometheus:3.14-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/prometheus:3.14-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/prometheus@sha256:6d0fa451d519ac8c1b1a9333994d0b673cf28cfabdc7176b099088edb8f7b83e
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/prometheus@sha256:e2d365199c964d4417044b6f284177acb65de474aa06b42491d9b59449f82d0d
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/prometheus@sha256:07ffb1f6cd4e31455d7b095826e331e52c6a98bc8647a3dd420337a4a5649c6b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/prometheus@sha256:51ccd77e96af7085f8f2c0bbdda5615604a15f85074e316d02f6ba01eb329443
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/prometheus@sha256:8a7a2ccf8ba93341c505c62a9f305f8fc14e747b016a7afbc0bbcf80f05a0281
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/prometheus@sha256:4b1c50fbbe7f21647e2f97bba206996e755a560961aad2337e523bd91d8ad13b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/prometheus@sha256:2aca9835209866fd09e79c15c2bd95da018627299828892972f9cc09b46daf26
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/prometheus@sha256:07f97eb29d18de4e9e7c2333230798a8bd9448f1f416771a3b4acc973f3feba8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/prometheus@sha256:3fdfc696459a426d67776a967e85406a4109907709a91c0008720898aaf16b63
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/prometheus@sha256:a7ecb1fdefbe47ba8f45557f7c1f8f48b326742caf0a4c0f222012befbacbca0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/prometheus@sha256:085f2eaf136f5afecfe92355f17cf0576561c14d654f11f1e862f574b3f41b2b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/prometheus@sha256:8ed9e0407df16693d9a264810e39272d62580fd1c077ab41c75eca8c5c08addd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/prometheus@sha256:6b994d2d61f959ebdc5598a96a0c2173ac85c331695fb022b332b25684b6c50a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/prometheus@sha256:c5589acc63f165520aa9ae495767d768c2cd58aef7cfad49eaf1c430efe250c3
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/prometheus@sha256:92f73772dfbb7bddb925ac6f7c9cfce7ec3265cf0de69c24c7cc5ffeb5135bc9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/prometheus@sha256:97cc8403d345f409cefce3437132c610e98516c90aea2a94e0503fd2db5e9a05
SPDX SBOMhttps://spdx.dev/Documentdhi.io/prometheus@sha256:2e5629d08322cd048f889fda770d2f8327ff9cbfcbaeec538ad0131e331f1a61