Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.9-debian-fips, 0.9-debian13-fips, 0.9-fips, 0.9.0-debian-fips, 0.9.0-debian13-fips, 0.9.0-fips

Index digest:

sha256:afe9a0131b266843e745925c7b2cdb4125f2516a99542539c7f26c1fb863592f

Manifest digest:

sha256:b6e57b9f7d284fdb98a7f9b54c36bdecb3307a8824dddf8c3c1329208ccad9f7

Size

26.78 MB

Last pushed

1 day ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:fc0d12d6e632420df4d48ed8deea75679299cdaf125ea4ccaa97601f2e233818
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:e390156a96cf2a38bb23f45a41e6ff0005d08413b4794c73d7119ef5e0e46efa
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:2aabbc7012801c434bb6a73653c368f343c8cea210a4ffc7325243c3609928b4
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:a8c037c7a5bf5ef9fe5da4d9bf503883c97588cc30f22541b2e9d625e67df584
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:d73533deaf8fda52f356dfc9a3092b09d961d424e3d51a732459641399a3cf0a
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:d6ca0b33fd625a5f3809b8f18e5502093ef6d307df8e2eb6120cb00c3c76d9af
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:a38822762e403706b1055add8f59e715de85190558d3d88e6989bcf2c913d2da
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:1e6cddc22c412581d06e51b2d2c21c2898851d994d2473c2506596cc922509c6
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:6179e0c9df495d48c106673f444ac3046a71e1e9f621d50893ee05bfe697d6fc
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:ea161949fdea1b53d0debfa9626138fee29e5ede580144a9523bdefec6548208
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:42c577aabc5442e0cdaff986226363df2dd206a712d59eecafd1702c179c0b4e
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:cb72b753cf2ce94654a83308313fb98d3a4855145a755787c77858fb3c564c69
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:45099eb0aef58a19708a856559f23b2d02e5f574968ad75268fe1ae1a33d2f35
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:a85382b87c71ec476f228d42807f627f9954e1591466f14f0c2437fe172d2460
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:59a10fb2e84e230a7bb17cd72a39648991e005b114137b345a32330604523143
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:fa47078a799ca54fef57168c29e97a7531cee69e19087e9fc62df1149cb62a92
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:0ff720493ad8f6d14a961f855aa362ee16fca4bf21ce54c01c0c488319ce4218