Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 1.19.x (dev)

CIS
linux/amd64
debian 13
Tags:

1.19-debian-dev, 1.19-debian13-dev, 1.19-dev, 1.19.3-debian-dev, 1.19.3-debian13-dev, 1.19.3-dev

Index digest:

sha256:9e00dbfa5d0b7e48d0f96e6f2cbf42a6ed3a2da6b9799af78f5690bc23e0004c

Manifest digest:

sha256:bee54309b131949bc831fd0a1d605cc2c9347b83a146a9040b37074928584b22

Size

117.90 MB

Last pushed

7 hours ago

Vulnerabilities

0
1
1
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:1.19-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:1.19-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:eda5c3f68feb2607007e96f9cd5801ba7ec690353084f101701e7d20d7e58c1a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:fcf4c943d70644114510f8db6cf60cc38ac29ddef9cba20dae37f739c3c957f0
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:b66e0cf76e4271104116481c4795a0dfba1df07043e3be43565adb3e1e5a7c03
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:8698d2ab845018059b1e7e223ce0dd732533e6ba81dacf311270d7360e503cfe
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:886ab3255cf710d2e955e3ded814591863e9dd7e93781d904f0debb46d8e4d61
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:3011956b06ef4a50f8e08da980144a5f993e597ef8df6b0bd764f8911734c27a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:994f6d0d935f74636f3a316e70d92f94c5d1ebdc2ec17130c86042ca85bb7c38
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:8f32db9a66230daf15cb90a811682069299a9db851a14503426e610322f00f22
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:c130499ed1545e2d009aa10f10b6515dff12c7bb0b08d4a7b888ca99764f9f36
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:a5a86d7d876ac11d6d952b6b7b8321d5749b5b23f87a5ab5e6a9f843e25c44a6
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:b1e8500931ca99909bad22907ae2d65ab8782c864d8f15884cd92b956dd250ff
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:94b49ee0102045de8884b752b3c4d7d180a3f5ff7ae3ab568e0fe0aba8a1f31f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:28ccbf2734ef36a1eae7cd9a93dadc9c50a737ffa9869a599573c3a727f28eae
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:825291519667877975241779ba54c50bd9ff7755a173cf435faac01dfbfa60d1
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:54fa5c464df1697d46cafdbdcdc77deb8302a69691f982b137445c3d2279da05