Sign inSign up
Metrics Server

dhi.io/metrics-server

Metrics Server 0.x

CIS
linux/amd64
debian 13
Tags:

0, 0-debian, 0-debian13, 0.9, 0.9-debian, 0.9-debian13, 0.9.0, 0.9.0-debian, 0.9.0-debian13

Index digest:

sha256:3bbc311640a292cc3aeefd56d5ff7a729931ec54911f738e2c3c72923a989d09

Manifest digest:

sha256:b15e0244d5a5a97780d255214805c7911ec960670f7cc6f3e35ce18d466c9fc2

Size

18.60 MB

Last pushed

18 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/metrics-server:0

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/metrics-server:0 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/metrics-server@sha256:d02d5ada7745f0532d9d5591cae27c88ec5edd84d8c036b522fcb26f9d5b3eb0
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/metrics-server@sha256:fc39d1842679bdf48653101062e8e018c0313d38273851aea5b89dfb64a8c056
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/metrics-server@sha256:8c52fa912543c5f7b45cb0c0ec2112b271c61b0e71176baae5b9796b35d51a4e
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/metrics-server@sha256:d22e75c663e433303438bd6c4d93768328b39912ceb9706b733865047bad338b
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/metrics-server@sha256:cf7c6b2f12e1b51acffc15a7ed6114863b9e5eea137b3f33129e9659a8f4c655
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/metrics-server@sha256:139044a5cf806861c37d0e5e93141b68f0f37aac4c715b6dbf675e1382125342
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/metrics-server@sha256:ae1c20795fbb6bab88b215319c94b36fcf566f88319339ab5459fcd4be0e5dd8
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/metrics-server@sha256:6d05fd5837f3594f3803f42df71bf86b1a76e896f3b875af6e3d73da56aedbb8
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/metrics-server@sha256:bd510ce30947a7fab34941a94a86e8e585580cbd02dda716f6b572c5989b9f26
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/metrics-server@sha256:1830444332f711270fa923924cf5d73694aa719ecf748a32360b76bc34ba5811
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/metrics-server@sha256:495500e3bb1ca9c6dda98a4e3fc6661020be06926ea0f87fb1d98d64cbc0befb
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/metrics-server@sha256:67cb0b1665de7b46c7f5d68360c6dd981b111ef64f5ce5419b8b3aa5f0b6f515
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/metrics-server@sha256:923ee2720ea0a1bc7670ec35e88f469be418e514326cf8a141535d5c3ed1b7a5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/metrics-server@sha256:e8df276fca814cac3edf45d3dfdaa6831a5e81f50d8974f7e8804256ed8be7ae
SPDX SBOMhttps://spdx.dev/Documentdhi.io/metrics-server@sha256:85ea478e5702c1042eb73fc5a6bfef77621024381ef7a0f438cb38b9f2844157