Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.9-debian-dev, 0.9-debian13-dev, 0.9-dev, 0.9.0-debian-dev, 0.9.0-debian13-dev, 0.9.0-dev

Index digest:

sha256:1cdde5254c50e4007205c21a3dd7e5fddaf4c916759ec82b305c5b6a1bc533d5

Manifest digest:

sha256:440eebaf1f3a0952972bd5e74b00b600ea0163ccd1538da0998ec62a3cf7a7a1

Size

59.69 MB

Last pushed

6 hours ago

Vulnerabilities

0
0
0
2
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:38a30dfd16156da777e10d61233c6b02f45aebe3eb8afcea579003c6c2b82775
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:25fa4768bc3a6820fb49e9ca45bf918fa25751798660f89ae533daf26bab6afe
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:642fb5712e7e189d5f0bed6d9caaa7ab560ccb56e318391249b78dfdfea83933
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:15cc6dd4b55f813201be8183e3ac0d22f4df11483e71ce3569121800a31c0ac6
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:f89dff33fa7e2bf41b1ad15ed2e307cb593434479fe8f0e4964c9f0c2113e7e8
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:d316ab65426dec88281e46f914fb2d1ef34e85ac53057229bab835d78adf60e1
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:316c08643c4e53a1ee353e8b2c432c49baa9d2898667d1ba17d21c7cb2901491
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:8208235bd0d8b8821031ac2f29e353bbe967c8b5fbe219f418f2b8ce9aa50b18
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:eb47aafa21c7ead67cc0955d9022f0d3f2f432fed21b4be19c6f8f3fe02ce90b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:9acd104eb03e36b878e79559bae3a38190736aff08aecde6b9e1889758b7d534
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:fdf94c9fdb265f1e929b09bd965080b8fb712c6d1a53e2cba81850de8214b580
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:29104f3d78189c3761c379e98e93ae577482491a333424c3d84725811acef8f0
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:096b8d08b3a9226273a7929562585efe4917d68dc1b22b0b683fa8b088968539
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:2d58b31f0cb6faa8752d615620ace988b0129a4d585e66665dde805b35d2a945
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:6aa9b61fffb80b6c2f795e96e563f2a48ef6c9df0328b59630f009ac76a4dcb5