dhi.io/codecov-gateway
26-debian-fips-dev, 26-debian13-fips-dev, 26-fips-dev, 26.4-debian-fips-dev, 26.4-debian13-fips-dev, 26.4-fips-dev, 26.4.1-debian-fips-dev, 26.4.1-debian13-fips-dev, 26.4.1-fips-dev
sha256:c2b2c5047b91d16cba2cf7e0874ca51bb6ce4ea75d9d739d747c4467991c52b0
Manifest digest:sha256:471d9e63c1bfca2194e088decf8758161bf00e18fb62ac21a9aa174c59e154a2
Size
34.13 MB
Last pushed
3 days ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/codecov-gateway:26-debian-fips-dev2. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/codecov-gateway:26-debian-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/codecov-gateway@sha256:660ef100649420974483f8ac0c8c881386a781907e23abe6efcf247eca0325d4 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/codecov-gateway@sha256:e20970a63f6e72a85eaff3ca39b1bb5245dd6197ad6ce8e0de14be0ca66d1828 |
| FIPS compliance v0.1 | https://docker.com/dhi/fips/v0.1 | dhi.io/codecov-gateway@sha256:0f76cf9bfe537cc194d3e265ea9cb36467de5e3b75accfacb4ad1bf6fceff1ed |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/codecov-gateway@sha256:fba885d787033d3113d6493d42545d789fe68c778d397a51d69a773297f71d70 |
| STIG scan v0.1 | https://docker.com/dhi/stig/v0.1 | dhi.io/codecov-gateway@sha256:c9c3a5ba556f27f8ac583650e3b55b420a19ac36c283513e0385bf5f784d2188 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/codecov-gateway@sha256:06f493e036ea59020f00f6f612aa5078ad516d90f456b81eb9040281432c31c0 |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/codecov-gateway@sha256:45bd94ec7d1b6bfa51eb8ddc2ee4f193159120e2726c49d43eafa0b7926fda69 |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/codecov-gateway@sha256:d67e88202d33e02f71b932dd736de8a2b82bc74e0993f77e90be955a28e4ff60 |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/codecov-gateway@sha256:9a21aeb2f98891d4563338078c721623d84a480ea6569d4d3b936d7c22892b2b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/codecov-gateway@sha256:e69a5f0c9079ff722e50300319f674ed81c0c1d63085e2ccbabb1013b98899e7 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/codecov-gateway@sha256:1970204eb39f00df704f5b9a930c59a1b864c6fc7487d6dd286fc059b0c907d8 |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/codecov-gateway@sha256:6f834d8acfba5db0df3628ed68ac8bf16d1ac5f524a4ad64bb3a45312984f7b0 |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/codecov-gateway@sha256:5c0fd1c392698d20846f52a43a6fc21b40845b1d3fe7c4b559cf613391a11fad |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/codecov-gateway@sha256:c97bfc0888bb83fa3ef83ea4ffe0d2a8c52743dd676da1f669b958a8b7e1de0b |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/codecov-gateway@sha256:8c4566aaf5f40bcabe6543bafddc272ca986f3115da870121f21705a533049ac |
| SLSA verification summary v1 | https://slsa.dev/verification_summary/v1 | dhi.io/codecov-gateway@sha256:d576743db26479f8ba80ed5aa0377ecf6c8b36e15b4932467fa462cf92d3e32d |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/codecov-gateway@sha256:71d0633ef4a921c0b4ee0b1223ac17d3de1c3ced34509b44d15ec5ee3b79210c |