Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.16.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.16-debian-dev, 1.16-debian13-dev, 1.16-dev, 1.16.2-debian-dev, 1.16.2-debian13-dev, 1.16.2-dev

Index digest:

sha256:aa940c03d10b06ce36305e7da770d69f25f9e228ac8c539eed4e652b765ff724

Manifest digest:

sha256:653604ec0ec39d6a0051fe8ff7748af393c606bb69a00005f9b16d660b11a2e1

Size

114.80 MB

Last pushed

2 days ago

Vulnerabilities

0
1
2
3
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.16-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.16-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:08110cb64ae309adf3412330d5fb02f8c953dd6accd268ee3d6fa1c6b8998a39
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:fdeb1802c2062c4f01b65341baeb6b05bf2ca27cc6aa6b508c9452c17c582312
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:a074dcac59a2af9868c6cfd0db2782b7b3a171cb334db24174455885ce2510f1
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:f7090418783a7078aaaa99bd58dfc779c05680be0a00d09e5369ce64900b6ea8
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:f3965cabc631b4981028406adc529da7749fa81a238654d55948d8e97664e33e
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:8dcb020383a8ea1cc2e5466d422020f1c2ea304a6d8aa1707d5ce78b5936df4c
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:c1acaafcc6488e22c17918ef0fda81719ced5069fa8905a6db417bf8ee029ce9
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:1063215e4774934a418afebeeaa53f7e74de4a9a0a494a337dc6e1abfebfd4c1
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:e42f2a698cec04dc7d99109403af1e5730cb5eb1acba52b78fb787547258d839
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:bc2a47235303c35da2497900dce03b4940115c7fdd393cbd265eb8b4427901cb
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:b29078fae10f13aa2f453b5f1149406f2d792bd11d619f3e013b11897b84f960
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:47a90224716849d2bd82a336cce6780258cb4827bcc3cb8a3199d211ca843782
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:9de02cdba902227352e4d98383c19fa8117f8f3e116191ef8d6a3343d9f9f1ba
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:19ca68a352e7ac1f6b824533dad525d283761319cdc55650aa725798328d33cf
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:f2a4ec2cf6a5eee918cbb33741750d57400f4a5ce6e23ac9f5cc7605785e26cc