Sign inSign up
Codecov Frontend

dhi.io/codecov-frontend

Codecov Frontend 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.7-debian-dev, 26.7-debian13-dev, 26.7-dev, 26.7.6-debian-dev, 26.7.6-debian13-dev, 26.7.6-dev

Index digest:

sha256:e828a5e0a7a49f97c9e43efd611351d543a646ed77eac8f31120e23ed3e9abf7

Manifest digest:

sha256:605a0389c0a7a7a17b88b23b9d93c66417020aa09a8439ff6ae0ed6bdf73c064

Size

27.36 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
2
10
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-frontend:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-frontend:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-frontend@sha256:98d898ba136984862b46ddf34f01e13621f5e526ef63f0466f3c40d5df053211
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-frontend@sha256:ebf0b781840e7f15ac3335e18d41f7879443dba4393435260e8d46cfa2ee4db9
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-frontend@sha256:c35325ade7fb0b3818068220cd78f6ac4af04d9faec1ed8d0ed2e6c2ec6ad603
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-frontend@sha256:c8a5994cbc950d29d5bae4a09cec5fe527c296c5cbb74c3c5e62f8bb0016b458
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-frontend@sha256:c9ba902a340bf4d339a01fa40a8a4d0eca9073218de163cc28a28cc85717086f
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-frontend@sha256:830a630acae3cb4f113986046d324b43442a7d9427b005296a4ca4a0ac01619e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-frontend@sha256:a194c2f721e29e15a869d94323512ede5a7f319fa9dd9171534fe8053107e0e0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-frontend@sha256:23303ca9a7f987a7420f7eacfbbf09ff3bb5621468622cd631bc0b00d088d5a4
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-frontend@sha256:8ecf22ae3f469a088cd8a04a31ac7471744288bf661af334a3e9a8ad6400f782
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-frontend@sha256:c8decbc5efc457050151bfdd2eb52ea9ed8be62a32a0ded5bde7aaf6c7ea9f5a
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-frontend@sha256:8a13ddf1a4c54c33f0140dd11ba15dbb201cff8439300470ffc5921d7ea0fa8e
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-frontend@sha256:7fe5d7c3ed47c79630d357f8501318f0069aee39a0f1cc90e73153c33aa13732
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-frontend@sha256:87962b47c601aa18f7726f8e7b7568f854b1461155989a3fb4b76ffbb3e2a8a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-frontend@sha256:c2bdb93b311aba10832716ef0a3230ff901dbd402c9995e7a56d8076c2b214e8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-frontend@sha256:9b23534cb69457ad72d71ee05d273dde7e7b60e804c96383ba770b6662149f8e