Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (dev)

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-dev, 1.31-alpine3.23-dev, 1.31.6-alpine3.23-dev

Index digest:

sha256:db274801287e91a178119b41b5c69bed8ff97b85de9c660d0573097b26f617b9

Manifest digest:

sha256:9102d7cf84b14e1c09218ea80bfc5bbfb7fdb0c284ecd0856af4dbb5862bc9d4

Size

4.65 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine3.23-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine3.23-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:a8d293bbc81528a93708488ad84e77fc660adcc707cbb2aec0c0df25397e59cc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:8286b0e19582ab058beea52554bd6866a483b9b66bc0b797e37f3ee80c3a893f
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:fc2ed273e3dd5e12807ba9253d14a78fb6b53bbc101dff52e515fcbbff1a0a4f
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:af8de15295d988f5ee2c45d67b1684e19446bc6cae71d2e58e62fb560eece15d
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:45b4b7b59fa5bedc3fa54f10d8ce6d7ae24b099d654603ae325e314a9a7a5ae5
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:2216756fa7b92b24845a247abe7e725a255101412386e3d3f0e87f451369c54b
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:65d50f72f265e158c81639c2066b0677842293514a08a0a28e13c7ced6f9e10b
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:30ec6ec24fd5c8d03f026f53d1ad8f3ba6a239f1e4fab8b8291058fa7cff0e51
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:850eaff70f21d2b480006013007abdee9d0b14599dbbd25bc59ec761f9910e32
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:13d8155af732bf370d724860520f36faf542855bb5abda327976ef87b131d95d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:0b295afccf7d8ae7bfc7b836f6cafc8ce5c126bcf3f8644a0329b8130c033006
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:4d74050b77eb7a5c4f5009cda9f20e72035935fbf306efacc110378c97456a78
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:86873ce8f5dc3b25dae766eb169ed493a949ef59c5a61e1281b78049228625a8
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:8c8be644b603528aebed610470ad34164f7856c466e0812d7133d2e40c4c5eb9