Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.4-debian-dev, 26.4-debian13-dev, 26.4-dev, 26.4.1-debian-dev, 26.4.1-debian13-dev, 26.4.1-dev

Index digest:

sha256:1a00038fb633e66c52e899d09e7640d3bd68aa94173f81dfdabc949148655ad1

Manifest digest:

sha256:7f157f73cdc3ec99696e2bd0e3d8b8e485852705ef44b924d03a8504a0d0233f

Size

33.38 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:6ea9f5148667a9eb494862f5bb4c99e3fa8ae65cd7e76a69d6efbff71ffa971b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-gateway@sha256:ec7c20896599a772fa65aa4e8a7d70e78f398b4cce34a6f35234b6c16b514be7
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:0cb87a9ed1384dde0fcb4b1117d79fc56a50a481e07864d45769b90102608526
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:6fe7071221810e095b55b8a39f4a9d06c4d7e705d24619102c2a1642ed7ce18e
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:ad91b659cdc55a157754801546709012e3d0e5d15eb474a665d360fb8be721b3
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:0cb69e981815b922daec9d2ca6704a5c892c4d98304302e849b74c2dbb18e928
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:3b7bc032a0ea74adeb70d063fd73fbd537344e6aa1d7efd271e99c7885ccabc2
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:1cf0a8e363b266e414e7478b7ad4cb476b409c6373aad30a6b05be30c830622a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:192c83b3d337388740c07f8b2843c4f623368f2fbfd81b22350c29fec955ad48
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:1fe49231ca51a8f40151145f657cb785e3592049d49867f4a651404c7b14bf47
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:37a9e766ebda9b1278d290803d0fc376cc70c619983fcb8e88761bc66dce47f2
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:3d040ca0530ee7ddf308594043ce46a23c9daa6bf998554146f7defc4f4db235
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:a84bea99b95964970e74e8e9dae68d89e5a2d8f72929125bfa3f8e69c90e3680
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:5eea158e79b5c18cee1cae70ec349d129b1d2f65ef53f7db07049a6411dab196
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:f898c6aea6ebad6f396b04aa25a0b635780c4096d0b0c68d34f7051ff3390b45