Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

0-alpine3.23-fips, 0.9-alpine3.23-fips, 0.9.0-alpine3.23-fips

Index digest:

sha256:4f01ba366a95c5bb998c2fd482921257a66d6e7c051ac7cf345bb368707cad21

Manifest digest:

sha256:2a31411e17add1fce369ce50ce72435c48a6c0e02d4a55a976d9fd8573b30c6d

Size

21.73 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:c449a819422266c5191c0ca2e9859d3ad2d3da26d31d6d7cad93e220f60d91f2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:7bf8f2904a1b565eb4d514a6183a2d6d73a8848eeea3d306ba93f1a4e676aa42
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:64a4fec4b321abc667e92af9bb1e50214298022a0f878a2663340bfc7cc9460b
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:234eb90574ffbcac7a51ed3b046ceb7e44773cfade8c2c131ff258a439f04f6e
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:1d50aefe7cfec3a2b6c6454a9fd6c41d255a5196f3f1625328897af9a71a200f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:f935d627c506fde4fbc30e9e89bc27d90c5d48f0fa1e15a6f5cec17f8a6fe070
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:4ebfba4c485af5b2d99f4aa0f18662adfd1b8a1bbc5e992a9bcd656cfce0fd95
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:24519185c8f016a35414406904ee3980aab97fc71c272ddfa855247dfd212158
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:31615f076750688f7d1139de3a81a47c13bf7f3e97f8b0fc94fc5dad25c9fc91
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:4c11bd8abb0bab0d5f05d4d00025ced171e2bd55ee34c4f52a76a06f0d7153f2
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:6ef2df6932c31f2d1ffc32ec0f2653967050c8e7f5163047197d07cd7a746c91
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:d6c1d20bc52e3f6e02844fbb23ab37bb02781115ff280a67bceda6d12b0845f2
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:9930aab4e32655008067e7863a9a98c40f27a55cfa509cef83ab6d0487a1a8f1
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:732aa9054527e29c6bc00cdbc187529a447bcd43b641d7596e9104811452ef7a
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:913e990e0e041624d172ce6101db347214b519be78b562a96244fefed9210cb5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:6de856480f17d76e2396395d1a459ac7ccc398d820abd356b2384cff54eee4cc
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:b2d844e8ebc8c634439ad20b0fdc3d50961c615eff875913cde5e9be8272f2d8