Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
alpine 3.23
Tags:

0-alpine3.23, 0.9-alpine3.23, 0.9.0-alpine3.23

Index digest:

sha256:374aef6581cc1cbfd2f5af82c5c86b88f18165c406188b4054e6ef7a4c3b1265

Manifest digest:

sha256:f45909b7eb5f01bf6efcb2a0486b6cc6ead1be3d4e54a1be83a7f1ea4c878213

Size

18.31 MB

Last pushed

20 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:a564d0faa291fb68cfddaca32a112e531a95b4e37bc8845f5562596e94247cda
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:f8f07a5479fae91eb92b717757a359579d020a2fbf3fc7ff4d9656d01fcb3e3a
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:4d6a8a549a0ee5af02c5854f57877b905c20c16368f05b6cc501562a46581ae8
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:73b5c05b1d51a361ecfcfe8a3b49b4a23bb633d0c8907f46f7c6493eb1d07898
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:90321766da0f602c8924f171b711ea5ced0a447e1b44c0aead0eacdbc8204cf8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:f9abdc9a674fddab897959d917765836e06a6c543dd4268874292666b9ce4d0e
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:189211666a9ecbc55270794ef0e1ff38e6a47c614194b8d005f16cdf9c4c6682
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:3bb90fa19af9f2784d957b67bdd9fef4948ca5bc61b63a64cbc6b53c1bb24f0a
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:dfbaca4b0149b21b7e348b66aaa26d3cc7e2b109015bd87a8adaa88b5cad61a2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:e662bac239df7307b4ca310dc178194f2c5cbaf41273b025ebbae9160df9e1b3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:7c08d3fca3998bb08a85d59eff413b3d8708a4285ff60d46d303c8f1eb22d76c
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:3a1a3eb41e15a098de9f070d39e704ddf91928b1605df3d61e7179b33d320cdf
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:c8ccd5ce7972e3c1f18019bddf83d6ef896c48e607f93ed5e39c5eeed4cc1d5f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:56bae9cc5a1cad403305608cd1235b709e0d90cdb197780815a103aa816b584c
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:cd497a846b129e23df6a683cd3a4db8d2174eeeb488ec108a640a1ef5a3aff6f