Sign inSign up
Nginx

dhi.io/nginx

Nginx mainline

CIS
linux/amd64
alpine 3.23
Tags:

1-alpine3.23, 1.31-alpine3.23, 1.31.6-alpine3.23

Index digest:

sha256:038603f848d825e26314760d357552da0f36426a50bb77cec883551e29b09d9a

Manifest digest:

sha256:68cf6055ce7857c7b8918ccd4374f0950b24f919ac4dd197a17401eaee1f2417

Size

4.32 MB

Last pushed

11 hours ago

Vulnerabilities

0
0
0
1
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1-alpine3.23

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1-alpine3.23 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:19b40f9d2bca43407b4c4b26d174d5bbd91a1b4e6c4fd58ef00c7cb89b276b9b
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:034ee8c75800c0cd807e6c4ab8b19bb4f58605233dc6762b4c15e7cf20006d2e
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:0583386e058acaeef5af7150d708db9bbae5fa13fefc0e6c403688cea45ca0e6
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:676a185f251abd4e8eba4d102abd3e25720889621d6a1aee94295347d2353a03
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:61c4bf66a5a7ff1fa1e0824f0a02120eacb593468d9685e18dd8e84a42e513d8
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:ec15e41fd9118c6c0748f1dfded4af267acb44b8e39e60c417de8c84d855a4a0
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:1672b8d953199c890616d3c70250a7b96ac7acc09aa6b240e7d1e3144cfeb069
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:1cf7f5e1ae762babe1f9f6c842fdf16b1665ac840e72d0932f6a845e515037ca
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:fdda3326668390ba0824dfe558f1faebb321e1978466b09c81fe0dc36e3b1b63
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:3bb14b59112edac904c9118320d13c137ad3d1d8593d4118014d45ec11db7971
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:4672fbb9e3a47e5ca1b09eee384120ead4b912c48b3c9432af20bc5b100fd752
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:03aef2c6df44e04f4e89426ca4dc744bb900a43b1b266204ba84697cdb4d85a9
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:b46a4f8ff3d490539622ea71babf53b4413b000bb412d4f9c07e436ec1648984
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:ec8a719ef8f096535528520d0f4133c047d4d444860c4c25da83f65257476d12