Sign inSign up
Prometheus

dhi.io/prometheus

Prometheus 3.x (fips)

CIS
FIPS
STIG
linux/amd64
debian 13
Tags:

3.15-debian-fips, 3.15-debian13-fips, 3.15-fips, 3.15.0-debian-fips, 3.15.0-debian13-fips, 3.15.0-fips

Index digest:

sha256:ed2b02a828d75d11bf6dee6097a7ac2b59a25a93d8111d6f96324decc276fa77

Manifest digest:

sha256:28c5a2d7498bce24ca28c3fceb1140982da3f3f5d81ded5314a9edfd855ad60c

Size

59.42 MB

Last pushed

4 hours ago

Vulnerabilities

2
9
0
0
3

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/prometheus:3.15-debian-fips

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/prometheus:3.15-debian-fips --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/prometheus@sha256:b8af9e6514d043235b0e93fd21bde6c9234bc7435267ce902c28665c25ca0833
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/prometheus@sha256:82789a8152e5e35a31cfd6f6cfba449a66bd7e936f71bb2ee33b5aa4bb657e75
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/prometheus@sha256:69ce33b38da877f7b218dfe885b4661e802cf3b7611ea34222047e63aefa812d
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/prometheus@sha256:79c070117f6eb4720059db1cf6d600f1c314fbe9591a7c5884b9a9a16525e5c4
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/prometheus@sha256:58100af73947289f214ca67d31c19c57348ca9aaf2a30e8acec1dd1543a6ea6c
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/prometheus@sha256:1354687216a6b84d8ad1d9d66b5c4d7aecec8ebfa1ab82bf64f2c8c722ab5ef3
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/prometheus@sha256:0a3da207dec220a15243a1ec12837c79b46d1ee20d66052d65ad017946f72b14
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/prometheus@sha256:72a79ea99523c2dfdf213574671a100f736e305504bed8c05d1e78fa0d473664
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/prometheus@sha256:d0f68559c2273d2bfa6cdf8beb3d28bec7b7891b922c0d7e282f438d4f3ef015
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/prometheus@sha256:bf8159814bc3d260af5613bc46e3ff94c2a81d326901e473c74c8a54a590d455
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/prometheus@sha256:f09aaeb246f25d1e83c8a914808cd0aecc18bd0d55010fe924f217034e87bde7
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/prometheus@sha256:198b9b00ce63bcf34f80f2bc38697c489cbb5063f390e51822e91476f8dc92cd
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/prometheus@sha256:9552ef0d9ec8ae80b2e6c005dfebf7c418c68d3cf0ad1b197b3efd8db52fad00
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/prometheus@sha256:81a5c0013379d4ff026673ce19f8c578af3c6d02e754cb6a8dec1b6dbc503870
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/prometheus@sha256:f3f9dc332601d36fc62f426f0dd423a7dcdace330ce1a8b58a72e45d33c4b86c
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/prometheus@sha256:8aed408d67bbf63159986f3149373984c83ca4680874b49033da7c7ceebb8866
SPDX SBOMhttps://spdx.dev/Documentdhi.io/prometheus@sha256:174c58feceeb05066ec35c4316caa35a9b3e2aba980909512f777f412ee6d55b