Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

0-debian-fips, 0-debian13-fips, 0-fips, 0.9-debian-fips, 0.9-debian13-fips, 0.9-fips, 0.9.0-debian-fips, 0.9.0-debian13-fips, 0.9.0-fips

Index digest:

sha256:f0050f6a4e5f53c946dd47c47fce52363b4c0c72cffe7c59ad4dc47959e1985b

Manifest digest:

sha256:e7bc4179e01094f0d49e0e94f1aa4d226a03ce9c212f909a5b99a1c5b40ea157

Size

26.58 MB

Last pushed

3 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:6db3d121edc4d5f247bb1e163c528fb389d71029648eddf829f8fd985baac1b2
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:fa8b18b3f840d2d86fb836ef394f43ff98e982af7aaebe13c5471fb7d2304130
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/metrics-server@sha256:ce603441be41aceffc1a2c90ca7ef8a04d8677170630125b763be0d7a5aae797
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:5d6c07784ad62de33dcd269a623b1e80484ae4ccd2560a9b30207f4bef1d2df7
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/metrics-server@sha256:645f388172650ce75438ea07f4b10c9676de66e27e4a63dccc60eebf466f1115
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:ff8757bfb8c71e7ac2252316db5b34555b303102add70afc0b41b65a5f9d545c
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:983c8c04d48f38eff3a5295dc69edc6292cf6243fcf7a17b6e1c2ef958604efa
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:d50cf13ae6fde9c009480bf73eb8e842c0c7cd4e12f8f1b55ebf3c393cb0e5aa
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:9584a5fb0633d17723cfe354aebf842ea22f66317d00187d649b6b36b230f904
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:667067020c1be8d7efdef53a30a07d9a0d57205e00a78b176681ff12972501f5
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:4336b22ec4050ce9a0bd45a770994943ec8d22723a509f65f99eff1850dd86f2
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:8d224f313027061c272c4b5781403bfd4c8c94e284e46df1539903e7fecc8242
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:a357d7659ab6adbb48ad1cde99c1c75e12aaed6e6bc643e692e300d6d69bd543
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:a195c5cbe339baef53427791487e54edd297b3a82e40440666d29c36737f5bf9
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:9fe06434792f9b9e54b74256b376d22ee2ec18e607552198fb9fd578c9dff05f
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:766ca4fcbb77e5946c6bfc5f82395a4e80b092e0d9ea3eac199cbe8d24c8721b
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:5174be56bcb906d6b550b49f73d21bca6523574dec3f6bc0cd703d10d1a07ef2