Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23, 0.9-alpine3.23, 0.9.0-alpine3.23

Index digest:

sha256:c608564fcb7055953d9315ea3e70326480996a5a301dd70a340bdfa71e5ca173

Manifest digest:

sha256:bf69e27fa212d974487b044e1a88f1f520dcb620ccf3cda948bd7e48c325ed77

Size

18.31 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:cb7000bd27400320d89829c3e48fe96e7fef4570c380709d093084f717913d0a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:cf2b5b7894939af413b97537a0054801a92543d2aa6df6cfd98118ef039f0eb4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:def46b2f2f3ee36a004cfc3cee81c3173af295fd92f5701a547829ce30571c9e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:1c322d3e2957312f7ab63d95de79e7883696f793a448fbeed54a05f4b77a950a
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:cc15f1a530941ca48ef8361b24860952836f946af406b8a59763cc06a4f4723a
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:687a354ae1f062e04e433d2ca3a6a51508e1a143b49c9c36d31cd55106fbd44f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:d29fe6274c6cfeb4cb03dfaaaf079a8cda4fd1b7ea1aed15f30b4b75d0fb2400
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:23c21d1dd957a0caa22b8e3bf38aa0848e4012a429bdadc3105eea0f1ad03ddf
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:1dfca86028f01881c81417048272f2ebde74c1edf92a9f6a6215f9dc9d804097
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:7fd0caf3fff6a504816b09f7952496b1f19c5a45fca095a7cb75f841b7931cbf
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:1a79bf0871fcb935c3466a3c68924b599f3af3a3cbabb42199603f154c5ffd19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:479c8bdb0bfff22962f111d8990cfb697b8e09f10351b10524c8ebe91abbc26b
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:a0087caa5bbd7509090a39487145de30e0afa984a9aea050ad1220f44688a1b3
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:2ac7d9d4fdbfafcb630287027b4780405c78466364f356657b9966df5ec749e3
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:54155dc45898e2f714a013f4c36c1d32be3b463fc059e93bf5a0fbfedaea0fe5