dhi.io/pushgateway
1-debian-dev, 1-debian13-dev, 1-dev, 1.11-debian-dev, 1.11-debian13-dev, 1.11-dev, 1.11.3-debian-dev, 1.11.3-debian13-dev, 1.11.3-dev
sha256:4bec5ce034eeface2a9f44a62c4c531ff8c36216fab79e43b4d1f09d56112038
Manifest digest:sha256:456cce5600da5dca2b449f18be2ea79a4d6d56b3a57941b713270e220cec0dbd
Size
33.85 MB
Last pushed
6 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:1-debian-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:1be96ebe1556c2f463edd0429309e00e266f68ec18ca6acc6362b71090cec53a |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:3f0b19d3a3f0093d81d013595fb9799b6c4f66cd676d35efd5cb04c3285d74a9 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:b763eed0b810524f72fbfcd93d8ea2de1f2cfdd6eb83814611d65413955b541e |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:003610a05a3e8624766292cb5aebf2f1e6645ec25549e549bec031d423e7b576 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:294ec37dd386359dc89becd08427e8413a728156de22fea7aabf109462d74ae7 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:55e7ad30faf8ecdb47ba6c1c86b839b0c7315604f624446fbdafdae3ec51cbc3 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:daaf9234553d9615c13687526fcaa5425513d0edebaa0c6d528a568fcdaad692 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:bf5a2621d4b03cdedfc1e24bcec7de50008f57c63cdb30678310ac8f3d484679 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:8d386a754b60f9c514c749cb235946c8cdd6b3cf3fd34871def97bc220811351 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:6b3f5409cf934d2865e0bac53c5ebee68c33a52b47fd2c99cd086b1a92f9b8db |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:d1bfa9766fba6e3a3b84b35ac3b04055e67eb57fd5d24f1ae82a0a3c08dcb7a5 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:1513cf9da38535d8fb4884ba5d056727ffd3bf336258dd0ccb1ce476637ba72f |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:86506cb31bccaa3ceaab768028ab23c139a30973a9e5d134fced8b52a436721a |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:ff9fafe093c84334678afc7353f2471a8c3e8b9eb4a55b13b6c81369f1ff477b |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:7cecd8842ac628d5e8c94a918a19b28e9ab335e98baf5e3bcc7ec72e7b6954b4 |