dhi.io/pushgateway
1-alpine-fips-dev, 1-alpine3.24-fips-dev, 1.11-alpine-fips-dev, 1.11-alpine3.24-fips-dev, 1.11.3-alpine-fips-dev, 1.11.3-alpine3.24-fips-dev
sha256:f56acd065fd910170720a3d5caed12ab3eac288bd70fe45aa4906bcf1691c851
Manifest digest:sha256:dc4e5e02b4a881ec70c88cc0fd300261b3050ee82b385572a0fd051c5162555a
Size
15.27 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-alpine-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-alpine-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:8c4ad372ad1ceaf44ed5a8c4f42c8136cefd9614f981065cab65089d9468dec4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:c378d0fccb636c1f31c01e926a71a923ac9a38b068bc0dd36842795167fcdc25 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/pushgateway@sha256:ec9ae0ea1eec2e6494e3225513df8bdaa32ae087413719149c5f31ccfda6fc35 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:5328e2d17cb4c00c8c6decfa89084fb7d3ced7999bae01b767b84c917caf6cab |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/pushgateway@sha256:ed5bcbb4434b9fc08dae4323a95cd6beeee68c1503871d6b1c687ab9222a1aed |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:80f24cdc6f93c93f732285bedda8901be74071fa4357233e95bcd652782d4ffd |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:87f9dcc58d954694ba44f3e86cd7c990ade4cb692281916570f162a39d3e0388 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:0a94897e2e50521ac1ecc2eef767f93299960d5ae7679946a7a920d8e1c2c3d7 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:9bebfdb8ff2c382b03b445a5b718e444882c2c2eb637ef24eea6b3e8ae8edb1f |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:866319a5b8da07ebfd5a610cec17bea45a5503725ae798ccc11d0fdacb4a297b |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:b9c1c3f49673bf33871a01f0368e230bdaaffa1bd2b0824dab705ba4537ace7a |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:dd7a9f9929fe8cb55518ae5cf8b25dc3402ef7e9e7b84d6c773d06f278a251a8 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:bf21a76e654eb6507ed326ca114b04297625bfa41156da21a21af42558fe5dd1 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:385be1ccc17d49474ce51b29adb2af32e10517a8eeb1a1a2ca05871e28e07c79 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:181992f6520b78955d10a98e70e93f0ecaf54316bfd4cf852e3da50a7c91e2e7 |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:a237b1b6eefab852004224f940fd0df270f843d26c996b5aed2ff54a0f17de3b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:ef324192394adc532b8f7ade191741746264ee5765361619785dd58c4c5c8c5d |