Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.24
Tags:

0-alpine-fips, 0-alpine3.24-fips, 0.9-alpine-fips, 0.9-alpine3.24-fips, 0.9.0-alpine-fips, 0.9.0-alpine3.24-fips

Index digest:

sha256:452cc211a472624343e6479ba50393252324b6b37dad258573e09be993fcac85

Manifest digest:

sha256:6b750b951d70b9426ece1884a863d3b8d3b800c84ede73da38bc50a4a0dff186

Size

21.73 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:d59e45d69f2a04d5b017576f764fed0daea2c506545f2b0a19e5d69cb3e2648f
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:078953791c6430c2fd43c3a31c56102caa3eeadb7a72fd6ddb09594c94ca7616
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:e3ef2ac7f80b1d50ee5c3d63b73f8161ace5ae297eac4abfa3b1bed413ac84c2
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:7217e4f6ab51a5f34cbc48686c04b74bd10990fe5d2d35ab868ede1a30b85361
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:bdcc70a7ffd99ffc8fd9a795afa5b1ba98b4ed6ff1d72e34415e786dec5278b4
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:fbffb94696e866d9ea7bc02829e1cbcc011d9ebdd377761d202ab6de34dacd18
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:e9d9e849a14a5f5288220d75688f2ee7f13477e380fa51e7523681c6ca3ce9a4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:06448258ec1a0156a8363f9e98c4658664646c4c7ade63da99d825807dc5a22d
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:e4a6aea112bdbb78635b33cdc29d9fb96f6a04f428bd5f8dda7bf5c956857fe5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:447dac7cbe0dc644afc7099697204f850aeb831e9a281de8e9d1fac154e49a12
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:f51d850c515b05ff8b0554f22d4a38744dc079e26871ec6eb59a5c9e7537bdc7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:886333ac2fd2d08306ef492eaf90897ec8961135a67c735019de4f1ae8830dd3
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:5d8e3ca5037338f014c9b6ac2f00bbb0dfb003c441e84de9b7b8cd0af6500209
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:a889533d187e3272ebc197951b54db1a9ea1463eb57a32b52cc4c0e7d054b259
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:578697d362a6b829c3a911f4496ada5f4acc7be6f7b9c3b85483efe79549bac8
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:b4065fc2c07c8a6e239f7cd563bc4f6f3af38524e472e15b8ce4e4357553a5b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:a69f76c499a041e114b18f843e54a18f0acce5025e6c823b4ac9ec7210da5efc