Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
alpine 3.24
Tags:

0-alpine, 0-alpine3.24, 0.9-alpine, 0.9-alpine3.24, 0.9.0-alpine, 0.9.0-alpine3.24

Index digest:

sha256:45e20492e046a56d95f18bdaccafd747987abae830d42925cd9214320b5149f3

Manifest digest:

sha256:1845623e3958c17507d59bb8aa7c8c892105b029c482e2fe580281f562b90160

Size

18.31 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-alpine

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-alpine --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:91ec34aafecd4c8c198996b3b30e4c7a13390d2127adb218428729f1a576cb97
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:10a8f7cb7d0c608ce47f1cb24f0d44d7884f4055d0df5b83f4a31a611ae1b551
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:4ebf4b6c4c11eb8da685b8089e5c9218983e21a5c2b34bcb3857d39f615c4414
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:dc7461b686bdbfcd9a1e06d5f600c05595fa881f2b2728434b6a9e12aa4ceccd
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:c76ef4f36b3f62ca05059ba21c8878a6b10bafa7ea783316255e763fc23f97cb
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:24b3f348452b7e4ed57265a0d6a0c66d2f6fff98989b93ecfa7f0b3681358e34
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:91b2416dd47df8eadb66091fad1957b1a7308eeb6875c7b039aafb3ec4e9d9ab
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:db9557242eac239514ff73fe3a3f23bcb70e35161c476b5390ca18a870555191
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:230b1bbbb15876429eddd4d8aaba3172fd66cfe123972a981525b902516372af
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:fb9e7d6348a57ca4540e8b9d5cc6a6e7fa33358a45aec2891645a546af4de198
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:141f9ec930a30035d037e39f594431c99a16a05dc3a9d0c9e6bac54a7e0be2e7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:3819211b71dec2a737c631488817103b806906037c7e78188c1b543d93b0b216
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:867285e95528edbcc3084560cd77f030ba11d13103d11c0686f9d37fb9a40445
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:bc35f11cea36ae4fc49b7d2e777d08cd5025c438665f46b495aaddca0d2b550e
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:d0b641bd0430461a6e044950eef24116b055d65c1e17d16bf1d7f487f3b73e18