dhi.io/nginx
1, 1-debian, 1-debian13, 1.31, 1.31-debian, 1.31-debian13, 1.31.6, 1.31.6-debian, 1.31.6-debian13
sha256:01378d311584144860a1516bb0240a4ce0c6070792ada0f2a4b763fdd3dcde49
Manifest digest:sha256:4aacd802e960f5cb86f158bbfdb122617cc5e2f7c84769b1b43c3e864514f026
Size
10.20 MB
Last pushed
2 hours ago
Vulnerabilities
Support
Active
Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.
Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub and also archived at https://github.com/docker-hardened-images/keyring.
1. List all available attestations
docker scout attest list dhi.io/nginx:12. Verify a specific attestation
For example, to verify the SLSA provenance attestation:
docker scout attest get dhi.io/nginx:1 --predicate-type https://slsa.dev/provenance/v0.2 --verifyAll attestations are signed and can be verified with cosign.
| Predicate | Predicate type | Reference |
|---|---|---|
| CycloneDX SBOM v1.6 | https://cyclonedx.org/bom/v1.6 | dhi.io/nginx@sha256:0b967119edc17166d1f539a1a6e0e6248a8f78045cecd0d574a2d8f41fbed3c9 |
| Changelog v0.1 | https://docker.com/dhi/changelog/v0.1 | dhi.io/nginx@sha256:006ffaac1bdb993cf54986912a8a085364cfc5f856e2e0f91383242dab5dce15 |
| DHI Image Sources v0.1 | https://docker.com/dhi/source/v0.1 | dhi.io/nginx@sha256:7cab16d115da3a119166216550c5580069a5f21ad17e8d57e4ee4284d0117af2 |
| CVEs v0.2 | https://in-toto.io/attestation/vulns/v0.2 | dhi.io/nginx@sha256:f04c9da83319534315d728dc87ddb67ea8a7dabcfd765aa0e36cd1cc2bd189fa |
| VEX v0.2.0 | https://openvex.dev/ns/v0.2.0 | dhi.io/nginx@sha256:64d11bd0763aaf0289122387604562f7394fc499f94087453afa86c433b2fcfc |
| Scout provenance v0.1 | https://scout.docker.com/provenance/v0.1 | dhi.io/nginx@sha256:73bf72ef3c7cc82b524e1349f8af91796cb49aeed1a05fdce25b278debe97e1e |
| Scout SBOM v0.1 | https://scout.docker.com/sbom/v0.1 | dhi.io/nginx@sha256:82770c014c0ede750a0fb3b73857a9f10cf41d0e38ea0f60701b3d2afa13211b |
| Secrets scan v0.1 | https://scout.docker.com/secrets/v0.1 | dhi.io/nginx@sha256:47a7fa7d74582f4e9dfc5de93d3d7c3695cbca801b29e0ee342a2a639729ac98 |
| Tests v0.1 | https://scout.docker.com/tests/v0.1 | dhi.io/nginx@sha256:e647f8aea3892a2e1b490caa538522cdce0a8ba13ebb6a77210063c4f413d40e |
| Virus scan v0.1 | https://scout.docker.com/virus/v0.1 | dhi.io/nginx@sha256:e2c47e5d5d3a788e2f034a5a662aa69dc5e1d97c46d9c527693f413e95462abe |
| CVEs v0.1 | https://scout.docker.com/vulnerabilities/v0.1 | dhi.io/nginx@sha256:71df2a2aecb7039106835b13a52f3e0380bced598ef596936d941bb6a83730e3 |
| SLSA provenance v0.2 | https://slsa.dev/provenance/v0.2 | dhi.io/nginx@sha256:c00a82eaa1f26116fcccb047853cdb798a280b7ed702f6fc0f3166e990df57c7 |
| SLSA provenance v1 | https://slsa.dev/provenance/v1 | dhi.io/nginx@sha256:e700b05c64b8af47c73a9637e43a665424ec14dfb97af5a42e26aba1dd368718 |
| SPDX SBOM | https://spdx.dev/Document | dhi.io/nginx@sha256:14bc921c4c316e2e3ebee52260b71246447b4a929ed9454699a33705cf79aa4a |