Sign inSign up
Nginx

dhi.io/nginx

Nginx stable (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1.30-alpine3.23-fips-dev, 1.30.5-alpine3.23-fips-dev

Index digest:

sha256:a9020ce6d4bfe18723505b3657c116c2ab10a97e6a3a340a863d48358bf85601

Manifest digest:

sha256:b6d91b78ad3aaca2ce295d00b415fe2e5af3870429c814cd106eecdaa8df4884

Size

5.46 MB

Last pushed

24 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/nginx:1.30-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/nginx:1.30-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/nginx@sha256:e9d7c9cd561713e6fa11698ccb5e7a0c76bdc326938e1885fa810f442b60accc
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/nginx@sha256:05be5492e379ed910c75cb768bd94cde1ecf513b597c95ec096e4395de4ac966
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/nginx@sha256:206f9a6f0f9019fdf362b33ef7551cdc7366c013b726a7dc0cdb6c8c15be30aa
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/nginx@sha256:28ddf9b7544e7d397e7c6eb7c16050a51de662f72fb061ff29dfcab8749140cc
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/nginx@sha256:1157e352e5ace68ec6d7a863a5f583afbfa73ebf5740941e448a95a0cedc5387
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/nginx@sha256:51563eddb4293eb5dd0b141beec5ebd9b1dfecaf909b58e51c7346efe844f295
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/nginx@sha256:3c5049b177fe6dffa8eb13d8f7d8c2bcb38e6fd340308f5d4a878f32ba2f256a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/nginx@sha256:05368d66b444e3541b2263308668b94c81eb39f596a3c180653e7ade08b1d433
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/nginx@sha256:ec64d0d7d5b7842212af769567ab8262e751e6473ddd787010b15a32e73d96f7
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/nginx@sha256:0217a011548eb3685af2b92d27831f551219592943f85c32f03492df9c5bfe9b
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/nginx@sha256:38ac0abe6826047946c90b1475a61eaa5445b6fbf723cc0b8992092601b78187
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/nginx@sha256:a69c06ec57e2a58a3cbedd8e161f3e10e46db8797b9f8e681c2d1d8eb12ef21d
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/nginx@sha256:c8a2d7f3520aa649eff35ed25e1775def304d88e2097b6f70e9d598156770003
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/nginx@sha256:bdbf9773cc26b6b3a134832f2d6cb979ce3020764dd14fb15635bbfef30be99a
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/nginx@sha256:f529e6ded1e4044fe51442462d7a45301de1df2220437cff1105f0c59a7c7e02
SPDX SBOMhttps://spdx.dev/Documentdhi.io/nginx@sha256:6dfefd4ce4bfc554ab50c11facb501a9cfc619a91f2d3c39d21a699539d8dedc