Sign inSign up
Pyroscope

dhi.io/pyroscope

Pyroscope 2.3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

2-debian-fips, 2-debian13-fips, 2-fips, 2.3-debian-fips, 2.3-debian13-fips, 2.3-fips, 2.3.1-debian-fips, 2.3.1-debian13-fips, 2.3.1-fips

Index digest:

sha256:440e6128a8bdf415338658b6f7eb860df0efa004ca7418df6bd9b2623ac4cc7d

Manifest digest:

sha256:5ac40914d1433300a4ffd0a3d42447b06737c4dfab58bdbafa35e4c1949e5b37

Size

59.72 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
2
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pyroscope:2-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pyroscope:2-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pyroscope@sha256:109e829a9e6f18f4850cd3bf899877c78939015cef1ac516b0c866359330d339
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pyroscope@sha256:5d081a60427e52249c860ed801efe19f4ff7f21a7fc0f46c49b7b571bcea30df
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pyroscope@sha256:346a9a875e708aaaff3b40a0fa438e007a007b3fddc352bbda2f3a69de366e92
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pyroscope@sha256:14cd1df962542d00748e1c3421a5fa1ec796e623b6a36fc38ea2757b899c503c
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pyroscope@sha256:0a1ba0c3a6c015ea039d2ae01e2aed6da111a666ed1b9503003337ae0bc1e9c4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pyroscope@sha256:dcca9c0846044bfeac0f4ca7920dd72b3ebe4e8871b707d3bc3f837455c23d24
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pyroscope@sha256:804a2754a408ea521591df185baf222af4fd6a08bbbe65dfce5938b6d86f0395
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pyroscope@sha256:cbbb02928e1ff4b28aa61fbfb9e15117dd97abd2824278046dd95149c6ddfdab
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pyroscope@sha256:8de0107cff9c031bf485619d9950fde9f84a7c1b2bc0da3d8af8996961840bdb
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pyroscope@sha256:3140c984ac57cbceb2d4e4d03fe9f006eef0c9dffb8cbaa078cf56237aa4fe38
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pyroscope@sha256:b1415f73470d085a41c0c83ee75df87747f0710a9b0a55c7982ab7092b106922
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pyroscope@sha256:8d2a4d7a854db87cc90a44715952b09294c8600dd70626cd29fc7cc025fa0286
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pyroscope@sha256:e4bff2fa7f985c65ffc70159560d7b6662c92f09daca637e9aa6b5eee1e0dc5f
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pyroscope@sha256:3f01d0bc3b8e627f54db920e79a78053e9df9084f3069353d9310768894a89a7
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pyroscope@sha256:52500f42c3cfd90a2329b0ed7e96f6750f09465bf882e6d8a66404e44bc07642
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pyroscope@sha256:8367087c597a76cbdc17d5812ce1fbec651f52cb521509ea38b1389295881d3d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pyroscope@sha256:21b68f810ce7e5bb679dca7f8f210b9a75ad73febe0d3e61135f507aabf67613