Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline (fips)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips, 1.31-alpine3.23-fips, 1.31.6-alpine3.23-fips

Index digest:

sha256:7faef5302e4d8fc79f25dbe6b9d6757a286c3b5ae9f0dcd1d258ed019c714786

Manifest digest:

sha256:dc1137c52ec74a1fc8f2423d9c965c7dcccf848010e588e9da67f038a73aca48

Size

5.27 MB

Last pushed

23 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine3.23-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine3.23-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:a120a7b090ec1cc62bccc76bfe22fdc61b3eb462122992de289d0d9cfa79e583
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:35cf9352c74febf1b89476ae2f6ac53bafc72bfa44462130bb6cc6751b1cc904
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:d9d9c5e21b26f0f1957a916d08bbf471c56158f72c541d54ee96690578615e94
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:646bfb54eff761ea96b6c15c9c3a4c6685ec2283233a6ac85dde0aaee725111f
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:146cdb54421dd99cd963c45dd36fa763e9a4e4ee244c73a49c2d959223eeb8fe
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:db3c1d29c63103d466b123d652bf4d567d3a87cf14f327fa6c1ec6ddb6da5cd4
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:f21b9f9304117844099ce81b72c41f59968fb59877b60f06442ee2a96d4718ee
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:c72ec9a4ac31394a0cfa01a905eeff506de066a6ed8868394520a738d6bf66ac
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:51a66f2430deac3eff75189b9e78890ab44e2b508e1dd0f4146221c8940e508f
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:709410fbb4d9653c4e674b1a994cb9d3c72b5e009655c680e27d9fec73958660
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:1577780f83556dc09290b1b43c39c3366581ed3ce5eb6f2ca1c03533e4685073
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:5c4f723dd9a2ad6c0c93ab701d2cdac46d69456b01f84feb4f49dca7abf5fc10
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:c278a1f57b69de1eae94588836fb486f23ae9a013ea4c467a4f3849fa678f80c
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:a585a884dba03936494cdad0c392360ec911836bfdb8eb6ca55bf4837dda7ae5
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:8d064888bde2f94e4d6b4ab923558436ac4eb3d15ac16b1a027187dd69fb19ca
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:ff2092386102f0e39620d1d883b85fc4ea831dd7a786d6ae5a74ccb10492d001