Sign inSign up
Prometheus Pushgateway

dhi.io/pushgateway

Prometheus Pushgateway 1.x (fips, dev)

CIS
FIPS
STIG
linux/amd64
alpine 3.23
Tags:

1-alpine3.23-fips-dev, 1.11-alpine3.23-fips-dev, 1.11.3-alpine3.23-fips-dev

Index digest:

sha256:b2ae2fc424ec91f04c9c780af2ab8ad53b6128912c5d974a7ca65fdeeea922d6

Manifest digest:

sha256:07d882de70e6ac5b093f9ecf70516f3a4a403221d0831f0bfc6d3323afd3c61c

Size

15.27 MB

Last pushed

14 hours ago

Vulnerabilities

0
0
0
0
13

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/pushgateway:1-alpine3.23-fips-dev

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/pushgateway:1-alpine3.23-fips-dev --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/pushgateway@sha256:fda363b5f2d7faa99d8c3e9a2ef1b8ac9d9deae1d664ec64eb7f0c450f43efe5
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/pushgateway@sha256:d445728525b7c9127a53afc7ed31c369c34f4cd0100a00c3c75714ecfdc13721
FIPS compliance v0.1https://docker.com/dhi/fips/v0.1dhi.io/pushgateway@sha256:a3e31a356f8fa8af5821fef6c9a8edc985c5fd7f53147449b2ed91c278dfb891
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/pushgateway@sha256:c4c677a44f232ffddc115c6ac82e1c8dd92d1a52f164937b4a00c2535e1b23e6
STIG scan v0.1https://docker.com/dhi/stig/v0.1dhi.io/pushgateway@sha256:0bc280cbd3827ff00fa7ece1caaf6059fb3470f192ab4fe423d77c68590ffb80
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/pushgateway@sha256:cee55ddf27f6bce5747d8c2bfc45ce108068b99a78be33c021892df66fd7c4c0
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/pushgateway@sha256:b85ecb7b96ef4a1a23eb6c524b6c484d17cc9545cc790245820e9ce0dd193273
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/pushgateway@sha256:d175e43aaa8b8f732037e6da867689ab496f6d80031f3bb743789382313a2d15
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/pushgateway@sha256:b8d7a976fdd61f368a8d784d83a3eb9ab4e7ec297dec0f29428dac363eaa99c5
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/pushgateway@sha256:6690809e85de09745ec7baa48112795e2f291bd76a9e526fd0643f64a7b2d5e0
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/pushgateway@sha256:29be03b2ea3e09421c4afefe704fb6b1efcc4555173d9c7e68f548aa8ee4b627
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/pushgateway@sha256:19eee82cc10c350923a16fa603bfe3c9bfbae9d5ff81a2fa5352f292745add56
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/pushgateway@sha256:32ee0ad582903600a76320c6fb558f4d9aea6c8300dc3d96b0b22ab3d8a6dd19
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/pushgateway@sha256:e619ee3cbb0a5a0258f885c159a144ce3b763dfb3df72d4f1bcf854ba0d95e74
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/pushgateway@sha256:595f288e07acf27094e632dc2f8bb54e964c501c74fd56c4c3bd3a843b7f8825
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/pushgateway@sha256:2b8607329e4cac73cfdfd733b9bf06a5d3ad8cbe91578d0d16362555bdc510e5
SPDX SBOMhttps://spdx.dev/Documentdhi.io/pushgateway@sha256:6e840bbfd8624b1f248305850c07b48884b15fe4df2114e1c7405ace9146bc87