Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (dev)

CIS
linux/amd64
alpine 3.24
Tags:

26-alpine-dev, 26-alpine3.24-dev, 26.4-alpine-dev, 26.4-alpine3.24-dev, 26.4.1-alpine-dev, 26.4.1-alpine3.24-dev

Index digest:

sha256:e73dd92f3dc9a5ae42f8e1557dfa7236c22bec215f346e31d335e2ee9216e830

Manifest digest:

sha256:95e02ce490dd8a906924f7aef8b507c3b292056a1d3f2461a8ae5a78a4e7604c

Size

6.42 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-alpine-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-alpine-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:5b8032bbec88874fcc5ce0fae50ce1d095cfe0b1296c829abd1e3c9fbbd0df7d
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-gateway@sha256:824db1c93ec213b00fa10a8f74454b8043c63f29aad6a7a512c58813ec11fb5b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:222b6b2e8c38b6fbf2d69c93d735ed620b5570127cb7b6c0af68c0e168845b2b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:2a9e7f5f3bfc9b03f2c96915b9c37f955b236dbfd3a068492727e32540b7b4f0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:5757581e750a136f34c87eabc300ccd5724dd5f5b598ca66832a0bdcbdfc7d7b
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:b07e420ff5ffc4caa9bd0a937505bd929bc7c8b94706920eaf5bd24e8c0eccef
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:d5d34791baa32d5ea6af79b460ccd1db63e752735ca344a13ed55590baf2aedd
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:cd61e09c966178b5f6becb6ada08434e459cc566c0a9861ce50f35ce9a71a9c5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:b05906f19d03bd0d625e3a4579aba6ee23f35825dbd3a4849b0ff351024d52fb
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:6d042b6a0f5e218b27d5a9d710dd6608aeb02ee136d7bcc752a67a5231479b8e
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:667b9cad01683867435c447f13e5bdf5b365d62f27165cbbc6e249856a6d796a
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:37fd14641cf34f83987174e102a1e6274df660c6dad1edb16c107479b4500c57
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:641bd8eef9d79c5286a365ac21f0ff4531e2caea27df11139f29e88d21c90c10
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:c49cb38e57b7c5ecb62a0b61a817dd62bf9b9294af5c02ae475785979ec82ae9
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:2345d5c69d0ae1bd0a5c5af0f4ee67894d24f370d49fbb96bdad9b41f15bdea8