Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips-dev, 0.9-alpine3.23-fips-dev, 0.9.0-alpine3.23-fips-dev

Index digest:

sha256:5e63199b3126907d6022999ae68860ae16928a6052b2fd64c190e45bc21064bc

Manifest digest:

sha256:19c042d192225f9121c5c87834e91f7fb54ff051c7b66af188c39cac44067c1c

Size

41.44 MB

Last pushed

2 days ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:a46d04e5d5b5451ee7245c9cdbaef7b9b6f524e400e2929e21313b0c150db6c8
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:f03380483dec89370d9a8c133d13e54605fabb75330c842e595a94f7d234bf57
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:476ed19581d2e1a24cf17d6b13c6f84b79f6c05e4c985aa3f22577f023a99b88
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:761fe95a73445b4da97e49df773eddb6e7ba1775e030d61e6800c88c23e97156
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:a75e5dfb34abbb746e79254c1722bee60501456342e770b307f0050f5d073b73
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:2dced59fda78258b44ae4360fa97ec7d0f9c60c9745c864f71c98918fbae2eb6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:0cc9c14469050fdf78f210aa20a3ecda972175a49043964cd8e593b4a8794315
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:27d4ef8d30ce709309c8f62aa40730cea72b4d6c55445ad9bdbe8cc3f433842d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:1664c31fffab308517114f051247b7de6b1d50a268345465d2e8560303b4afde
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:d9f7cb5697494da340e078dec7f7b78a669f08291aa295b7c765b3efcbef01b0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:8a607ff368cf3762d383400195516894f128b63ceec8f183f4896831f93df55a
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:30c86fe629f08a4b131adce54f73d31f85519ca49ec5a210ade836f00d12a1d9
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:f651b05d788ceaa9e4c3a20ca880ca462e3cd538c96e4c27a8f552a657fc15fb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:8cdef059b262d7e76d3913d59b77712288a84b4b421706ef1d86ee2f0e54de11
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:555ec5a82b59a7f967216469a3068bcdd2c4227376e47384ac2cebbc0ca5fd58
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:2d74a39e7e8255df3cfcfb917d137abbf2b1acd41acec7fa65594a6177014753
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:2c4c94da98d82e1f6833d74af355d38d4b13ea8e9e33d95eefda5674ed15b021