Sign inSign up
Codecov Gateway

dhi.io/codecov-gateway

Codecov Gateway 26.x

CIS
linux/amd64
debian 13
Tags:

26, 26-debian, 26-debian13, 26.4, 26.4-debian, 26.4-debian13, 26.4.1, 26.4.1-debian, 26.4.1-debian13

Index digest:

sha256:bb163719b9c41b44213700f6f99b97fa9289069c82351dd0dbb03297d716288e

Manifest digest:

sha256:1720bf208de290e45aebf236c3f407a30f15727a4c34a0ae897dfbc9836ee023

Size

21.41 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/codecov-gateway:26

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/codecov-gateway:26 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/codecov-gateway@sha256:da45b724236e26321682e461dc4328fa62091871325b762cdaafb07c7bd224ca
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/codecov-gateway@sha256:29052293d05f787d3a7197092b3136f9d7879482b1128c20f2f03f9b0454b43a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/codecov-gateway@sha256:bffa66ac48cfbc1a9e5e53f232386c0aa17b4c3616df412120f0664df6d90e6d
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/codecov-gateway@sha256:62841ac5a61d2f8bd3b00518cb7fb2570440884c731d79b2d5e46ea8d10fcff1
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/codecov-gateway@sha256:dac43135e7cabacb7d4d035eccf9ebffd75915294f0e657c4bc327cf3ed9bc4a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/codecov-gateway@sha256:e3d8a432e934679916604a801d89f33a38520d543089f34de36c967ebee5fd5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/codecov-gateway@sha256:94f714550b008a1c0c48287544436f103c3122a3c32be12d2fac9cd4e0ac56ee
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/codecov-gateway@sha256:f40a4a91862648abc7c7692e93d8f31212d7b7d9a9650005690426ecd9d703a7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/codecov-gateway@sha256:88b6f67ee88e38b62513a28ede2453c071b9f98074707faaab544f1b3ad1e409
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/codecov-gateway@sha256:83dfcffab388918a00501b16a1daa2ae482bdc5828d5b8ec83d6897b759affc4
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/codecov-gateway@sha256:e4e2f01e2b6c729cf2d090321bb23d61cd908383e27c8cbc869fca9f1661c881
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/codecov-gateway@sha256:4851e79ddd43915abb5d43fc201d803d5a5d5c6cb88c4d301cf58140121f485a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/codecov-gateway@sha256:913acae4ef0b9db2c34337fae102317536082c2a837eb2fdabe08b6534b6c8dc
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/codecov-gateway@sha256:d33725664b18543805d3ccfd8ebd5bbb6e23ed79d34c8fd3ab51d1e4c8483b9e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/codecov-gateway@sha256:0ce313c4d3bab441eaf4cdbc10faec73ce0cfd7bf46398961ef75697b55d0c7a