dhi.io/pushgateway
1, 1-debian, 1-debian13, 1.11, 1.11-debian, 1.11-debian13, 1.11.3, 1.11.3-debian, 1.11.3-debian13
sha256:6237e46f4442793e28dcd345d5e4673c3f8ca6b8111f5333db31a72cfe296882
Manifest digest:sha256:0dfe0ee7001ccd93797d0c4a96e4ba22dc232ba9bd2a7a0b8f74185e0f3900af
Size
6.92 MB
Last pushed
4 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/pushgateway:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/pushgateway:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/pushgateway@sha256:b096def36b281adcc1fd8ab70833a5292e82ef08d27500c8545d2eb859fae9e1 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/pushgateway@sha256:6576d28b82b343eec282811b6b3509afd6b246adf98e68a4d9e7d0d0e68b880b |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/pushgateway@sha256:58ac512e0881f082c6a58dd3d40f604ef3fef5bdbb658440635e4ba837f00c86 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/pushgateway@sha256:08d808ce8280681aa21bd0eb58640086b82ad51c4a749392ae5b4b1c2e952afe |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/pushgateway@sha256:db67d9aef8fdab51fdc67333e10e1fbcecc962dfaa7ca5c903d9b440c038adcb |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/pushgateway@sha256:f0cd30280c366643535585636904aac2304ef3b5b0b5f54a6161b890b236d79c |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/pushgateway@sha256:eaa0bf29a29a7559a0fc316f11f42ddc59ab8f1f5818b18faa70904bc2157144 |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/pushgateway@sha256:717e5ef8be21ccc863b749da065fa006e88bd3bf1d105c2c060a11b35420c705 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/pushgateway@sha256:e1ec2d34c9e2a89caa92c705135e1fa7274be274332d0daf6954b90c1c49886f |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/pushgateway@sha256:fe72063059577f1bafde499c38dac013f2514c01a9192e9ce0f9a16602df3f3b |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/pushgateway@sha256:d7c1ce8e1145ab738893cd80554816d9c03c6467b8494153c4a7dd87b57e4127 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/pushgateway@sha256:4d5c1ea4c836f9d203c7596b028730e56f9e009606510c6fb81ff27eca10a40e |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/pushgateway@sha256:186d6f17bf0948574630ce5a950caace6180a25343be2128485b4eca51de516d |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/pushgateway@sha256:fb8c7c617b65e6f4b4d4fda0a2d8115dab82afd81c95e983b82e3b5ac25989a9 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/pushgateway@sha256:20a845669e53d08359a5a5c9a46e5384a3415e2f889e05139e53bcc882ef2044 |