Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x (dev)

CIS
linux/amd64
debian 13
Tags:

26-debian-dev, 26-debian13-dev, 26-dev, 26.4-debian-dev, 26.4-debian13-dev, 26.4-dev, 26.4.1-debian-dev, 26.4.1-debian13-dev, 26.4.1-dev

Index digest:

sha256:908666d7a1143bfc76c58112d226ec4dfb7cc42c0f17327300d16d062622d063

Manifest digest:

sha256:d8fc51867878bf890c36acd9da9cac24800208790fc7f976b0278ca057bc9c6f

Size

33.38 MB

Last pushed

8 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:0adb57a23e2ed5f21a72ba59b87926e1d50d6373a62a0be395a9f51cef8ec03f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-gateway@sha256:9b25eda8aebceb0a385527d83cc5ba62e2800bcdf1c63a7cb33b3470be5bef89
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:e67e4bc2e6023b2fa2990a339e88d060d6960d40c4f2b16d06c4d0f64e6bc74b
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:dfa5dee55844b2d21a9e74e68bf39ba3e32a351bb290e8f92501c2aff6665e49
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:6e369b840cef38553cafa989978049be5bb364afc6488b5c33bb602c72ec9463
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:2fa3ba1c747c18e360f63d49f8debe9341b6acab3d47e12771466589d27c6666
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:b4a36e8919d35db4fa161a37cac60fa6f293d96f7266e86475b1ccc329d9f508
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:584850b267107a8047ca66eab22c2feff8e744b406a168c67ad0e163bc609e2c
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:74cf6657ac1c7979b2f705972331114cbe4454982c84848a8472dc6d5cbb2cab
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:34550d0bbf854d43522663c6e6fb5c446a59dd88d25c3cc4fd28901dba8cf271
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:bf9c6886c4009fd107ce711a0d44e61bfd4b46c358010d22a8d20f4cdb2c4ca8
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:5e4cbdaf5dcc62e3c67228d254813b295ce5f86525d7b8978f7d070b21e38b60
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:471ba1cc40b077ec5839e163a907723bfe587870de289208a6ae199e9f905a91
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:5b44373fa6dd3cfa45ef237f1dbf1c65222d75c4d3221ba2ab4098e4f1aa4b20
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:c66416cdfb297cf06b8cfda79818340fae7f2d7036384f0eeb3b6e1c04028e13