Sign inSign up
Metabase

dhi.io/metabase

Metabase 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.63-alpine, 0.63-alpine3.24, 0.63.18.4-alpine, 0.63.18.4-alpine3.24

Index digest:

sha256:b36f4146260a2d42f8f16705838ba1b58665918c5892cef401f4416b59be65ab

Manifest digest:

sha256:682e099265a107be3cef468ab332ec5cb51a90bc1be53c5bdd8d7c7709128b70

Size

696.15 MB

Last pushed

6 days ago

Vulnerabilities

0
4
1
1
1

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metabase:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metabase:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metabase@sha256:2988b9798896adf2739e5b52f522e19a165ee755e9406f99e13048b897de95c4
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metabase@sha256:224d7dcfa382835b7515c835a6538e1811a514bee8f4de040b76f45d0db57400
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metabase@sha256:25a36a61b3bcbf4b9ddcab39f20db3ca35c2a6cf882ab71fbfc356d712419c43
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metabase@sha256:b0b8b82797fa6576b643a0251fe88c931f23e316c76bf396a65c7d38bdf19e07
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metabase@sha256:626676a75188e5855661c2036e45dfc844dbdea54358ed546e3c88a44b592f5b
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metabase@sha256:83e19e1d7ddbd0832e09ec71eb8eef5514d5ad1f87b4a978ca060f7d49edba21
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metabase@sha256:2c02b11021496d3188419ae508a917b6b6beae40823c518b166876bcbd8ec1b7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metabase@sha256:c05a554855df39a2280ffed611086a9b600a648d7f225736850d5352112e564f
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metabase@sha256:7c64a48904efc3eda154973ed393f9ae8c29b8336c44f1699294355e09bcb0e0
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metabase@sha256:086f68088ab0822c04528d2b09fe1375a128de98d0b029a7e288dd4fa432cce3
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metabase@sha256:45800aee9a207335709b9ab3d951e41fe8df32bdf719e3ffc7363f9c80b45d6f
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metabase@sha256:737d652845ae31bf9884778b455042663ac497ba9a3023272a2e4ccab116fa29
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metabase@sha256:1c6f1d4e1d690744ad8e9128fab1cdd6e949601e99a77f95f3503009aeb57d8d
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metabase@sha256:44e07993dbab175e1d18ed89ec879a6188d6b0673a8c5f60558da7049eb49084