Sign inSign up
Codecov Frontend

dhi.io/codecov-frontend

Codecov Frontend 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.7, 26.7-debian, 26.7-debian13, 26.7.6, 26.7.6-debian, 26.7.6-debian13

Index digest:

sha256:56002b459fb59828149da95f875797322fcc191e4f76c213e89627b4e7ef3b89

Manifest digest:

sha256:96bec4d7e02b5dca5810c0ea6699195e930d37b5d27b5cb57945e1e7e2b15a45

Size

12.51 MB

Last pushed

20 hours ago

Vulnerabilities

0
1
2
9
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-frontend:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-frontend:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-frontend@sha256:a22736d19de2212de3a40b238c1bc1ad8efaebe8a6a490a02837f3fd57d22914
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-frontend@sha256:90122508d2924c91431d0c96dc441d8a21ea0e945ce2751384d6678513f2fd16
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-frontend@sha256:372e53701b6342b0a7e218028e9fdac47bbd511b6a8ba2241bebfc2cf5540a00
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-frontend@sha256:f5f9e5d2172aa7e7bc2c238d2e7ee362c10af803c371c5ea225313904aee5fba
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-frontend@sha256:d0775ed94612782f23699ed60139f5113a66729723c1a21e7b999a199bd238ea
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-frontend@sha256:5ba12d0861ad0f7bafa22ab687dc3b8bcdf59f7a36487f0dbaff50aa4d672171
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-frontend@sha256:b8cacadbc7549afbbe5f6c4fec8817425eb9f629b122a327969b51324abad05c
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-frontend@sha256:9134e999f12ff533475a73ca90e199f0d8f41616063d550e52d9dbfbc7df1c34
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-frontend@sha256:af1313414d563f77c561e2f2ebfe72c1feb591ab9d450c6b9cf8ccd800695cf8
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-frontend@sha256:35a11c90305a5fa425a8c58d818d319e7ccd7acb47c86ae23ceb65cd9bcde599
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-frontend@sha256:5df44c397576b4b1c64cfbcb96c8eb1915f3f0ec56c64f3f62499163e4421f86
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-frontend@sha256:c3d575797fe7f9e1645d3ab4d9026399cbfb44d6ae854ef82e325f9d29d3c2e1
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-frontend@sha256:187381b2a1b70e17642a15a181a4ced9174530c9d510a360a8a04e6a517932bd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-frontend@sha256:29ff59b72b7b5dad877dc642acc1ff1e4419db3971dafd9d508db898447e33ba
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-frontend@sha256:e931f041a0722170f5f92aefd07d081115902b2f07876717502afa87c4cf0eca