Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (dev)

CIS
linux/amd64
debian 13
Tags:

0-debian-dev, 0-debian13-dev, 0-dev, 0.9-debian-dev, 0.9-debian13-dev, 0.9-dev, 0.9.0-debian-dev, 0.9.0-debian13-dev, 0.9.0-dev

Index digest:

sha256:68955b3b1a3d1a3ac370beea0e5fd305772bfdc75226792c6b16f13eb370ba2c

Manifest digest:

sha256:7ce5d1fd2d25c5480ed84992662d73ac7de39ea5383edb14b4ec67487da9439d

Size

60.06 MB

Last pushed

13 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-debian-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-debian-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:5a7a5f8ec4adade914738ddface8462c51ad6df56c854a3cfca9ee8b96bdfa4a
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:84a93b138f4a9a2b20ef888c4dac9893605b1b10e01b9f1dfd645f607d27afcf
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:e62017c8f38024db1658b4a070d8fd1f4ee5722f6c710d9f8c96f85f936da6cb
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:483a9bd491e6ed70ccc7023d10ee42397c7d3a9b510946889d576da9a8aab2f2
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:e210b60444881e4d4a693402416a83c25b94f28850229d19acf8b2a20e1b54b6
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:adcdcdf68bcab75390ca237339476f75f88568543e8c9e81b9dfecb35a655b9f
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:501f6d4337908221573550b39f3d0546f24f691184d27980ab507c05e21cd547
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:8f8278b2fa18dc8705485e8a6feeca881844eb4852500ffa067b8ac0b2ed8d2b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:b599e60fdbc0b1b1e74c8b85dc51a460863fb43c251bc2befdba250e4c792fb1
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:53a145a9fce0397cb4973326dcd91a316c3ae63fb4a2f01bf0ff769434cc9e90
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:fed414d5ce1300ab030cf12bd1b4da5bf68b838820b46d7b016d4988ceea71f7
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:649782a7e897655343214445b9223174fca57a289bc24e0fc1b142a2156f2a79
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:1ced04bf5b6495cd264f6ee7067132b6e03206df5835cfe34e72bc1b4f5b6efd
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:7c267e2aaf84b9d8f4ae1fe368a17e7fb142a32027b31d7decd4494a6f26f0b4
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:8d17fcc3154f605ef8369cbda123d53a9a19ec404503cbe0f108acf261dc9aa4